Knowing who to watch: Identifying attackers whose actions are hidden within false alarms and background noise

Knowing who to watch: Identifying attackers whose actions are hidden within false alarms and background noise
复制标题

知道要监视谁:识别其行为隐藏在误报和背景噪音中的攻击者

DOI:
10.1007/s10796-010-9268-7
复制
发表时间:
2010
影响因子:
5.9
通讯作者:
Chivers H
Chivers H
中科院分区:
计算机科学3区
文献类型:
--
作者:
Chivers H

文献摘要

参考文献

被引文献

相似文献

内部攻击通常是微妙和缓慢的,或者在行为指标之前,例如组织违反规则,这提供了对恶意意图进行早期警告的可能性;这两种情况都提出了一个问题,即从长期从多个来源收集的大量事件数据中包含的有限证据中识别攻击。本文提出了一种可扩展的解决方案,通过维护个人或节点是攻击者的长期估计,而不是保留事件数据用于事后分析。这些估计随后被用作更详细调查的触发器。我们确定了事件数据的基本属性,允许使用广泛的指标,并展示了如何应用贝叶斯统计来维护增量估计,而不需要全局更新。本文从理论上阐述了这一过程,并给出了一个实例,并对其实际意义进行了讨论。这项工作包括识别被破坏网络节点中的微妙攻击行为的示例,但该过程不是特定于网络的,除了网络监控确定的事件外,还能够整合来自其他来源的证据,如行为指标、文档访问日志和财务记录。
Insider attacks are often subtle and slow, or preceded by behavioral indicators such as organizational rule-breaking which provide the potential for early warning of malicious intent; both these cases pose the problem of identifying attacks from limited evidence contained within a large volume of event data collected from multiple sources over a long period. This paper proposes a scalable solution to this problem by maintaining long-term estimates that individuals or nodes are attackers, rather than retaining event data for post-facto analysis. These estimates are then used as triggers for more detailed investigation. We identify essential attributes of event data, allowing the use of a wide range of indicators, and show how to apply Bayesian statistics to maintain incremental estimates without global updating. The paper provides a theoretical account of the process, a worked example, and a discussion of its practical implications. The work includes examples that identify subtle attack behaviour in subverted network nodes, but the process is not network-specific and is capable of integrating evidence from other sources, such as behavioral indicators, document access logs and financial records, in addition to events identified by network monitoring.
DOI: --
发表时间: 2004
期刊:
影响因子: --
作者:
Joseph T. Wells
通讯作者: Joseph T. Wells
银行和金融部门
DOI: --
发表时间: 2007
期刊:
影响因子: --
作者:
J. Sullivant
通讯作者: J. Sullivant
迈向主动的计算机系统取证
DOI: --
发表时间: 2004
期刊: International Conference on Information Technology
影响因子: --
作者:
P. Bradford;Marcus Brown;J. Perdue;Bonnie Self
通讯作者: Bonnie Self
使用态势感知 MAS 进行内部威胁检测
DOI: --
发表时间: 2008
期刊: Fusion
影响因子: --
作者:
J. Buford;L. Lewis;G. Jakobson
通讯作者: G. Jakobson
人工智能(第三版)
DOI: --
发表时间: 1992
期刊:
影响因子: --
作者:
P. Winston
通讯作者: P. Winston