Data-Driven Decision Support for Optimizing Cyber Forensic Investigations

Data-Driven Decision Support for Optimizing Cyber Forensic Investigations
复制标题

DOI:
10.1109/tifs.2021.3054966
复制
发表时间:
2021-01-01
影响因子:
6.8
通讯作者:
Panaousis, Emmanouil
Panaousis, Emmanouil
中科院分区:
计算机科学1区
文献类型:
--
作者:
Nisioti, Antonia;Loukas, George;Panaousis, Emmanouil

文献摘要

被引文献

相似文献

由几个攻击行动组成的网络攻击可能给法医调查带来相当大的挑战。考虑这样一种情况,即在发现一次攻击操作后,例如通过观察敏感注册表项的修改、可疑的网络流量模式或滥用合法凭据,怀疑存在网络安全漏洞。在这一点上,调查人员可以有多个选择,关于接下来要检查什么来发现其余的,并可能会根据经验和培训选择一个。每迈出一步,情况都会是这样。我们认为,工作的这一方面的效率,即选择下一步采取什么步骤,可以对其调查的总成本(例如,持续时间)产生重大影响,并可以通过应用约束优化技术来提高。在这里,我们展示了第一个数据驱动的决策支持框架,用于优化网络安全违规行为的法医调查。披露从已知对抗战术、技术和程序(TTP)的存储库中获得的好处,对于每个TTP,它都会收集威胁情报信息,以计算其与其他对象的概率关系。这些关系,以及从关于攻击生命周期模型上的对抗性TTP的定量数据的投影得到的邻近参数,都被用作我们的优化框架的输入。我们在一个案例研究中展示了这种方法的可行性,该案例包括31个敌意TTP,从6个经验丰富的网络安全专家的访谈中收集的数据,以及从MITRE ATT&CK STIX存储库和公共漏洞评分系统(CVSS)提取的数据。
Cyber attacks consisting of several attack actions can present considerable challenge to forensic investigations. Consider the case where a cybersecurity breach is suspected following the discovery of one attack action, for example by observing the modification of sensitive registry keys, suspicious network traffic patterns, or the abuse of legitimate credentials. At this point, the investigator can have multiple options as to what to check next to discover the rest, and will likely pick one based on experience and training. This will be the case at each new step. We argue that the efficiency of this aspect of the job, which is the selection of what next step to take, can have significant impact on its overall cost (e.g., the duration) of the investigation and can be improved through the application of constrained optimization techniques. Here, we present DISCLOSE, the first data-driven decision support framework for optimizing forensic investigations of cybersecurity breaches. DISCLOSE benefits from a repository of known adversarial tactics, techniques, and procedures (TTPs), for each of which it harvests threat intelligence information to calculate its probabilistic relations with the rest. These relations, as well as a proximity parameter derived from the projection of quantitative data regarding the adversarial TTPs on an attack life cycle model, are both used as input to our optimization framework. We show the feasibility of this approach in a case study that consists of 31 adversarial TTPs, data collected from 6 interviews with experienced cybersecurity professionals and data extracted from the MITRE ATT&CK STIX repository and the Common Vulnerability Scoring System (CVSS).