Employing attack graphs for intrusion detection

Employing attack graphs for intrusion detection
复制标题

DOI:
10.1145/3368860.3368862
复制
发表时间:
2019-09
期刊:
Proceedings of the New Security Paradigms Workshop
影响因子:
--
通讯作者:
Frank Capobianco;R. George;Kaiming Huang;T. Jaeger;S. Krishnamurthy;Zhiyun Qian;Mathias Payer;Paul L. Yu
Frank Capobianco;R. George;Kaiming Huang;T. Jaeger;S. Krishnamurthy;Zhiyun Qian;Mathias Payer;Paul L. Yu
中科院分区:
其他
文献类型:
--
作者:
Frank Capobianco;R. George;Kaiming Huang;T. Jaeger;S. Krishnamurthy;Zhiyun Qian;Mathias Payer;Paul L. Yu

文献摘要

相似文献

入侵检测系统是一种常用的防御手段,它检查网络流量、主机操作或两者兼而有之以检测攻击。然而,每年都有更多的攻击绕过入侵检测系统的防御,而且随着攻击的复杂性也在增加,我们必须研究入侵检测的新视角。当前的入侵检测系统侧重于已知的攻击和/或漏洞,这限制了它们识别新攻击的能力,并且缺乏对准确确认攻击所需的所有系统组件(特别是程序)的可见性。为了改变入侵检测的格局,我们建议未来的入侵检测系统通过采用攻击图的概念来跟踪攻击在系统各层之间的演变。攻击图是为了研究如何通过利用已知漏洞发起多阶段攻击而提出的。我们不是被动地构建攻击,而是建议主动应用攻击图来检测满足漏洞利用要求的事件序列。利用这一见解,我们研究如何自动生成模块化攻击图,该图将每个组件的对手可访问性(称为其攻击面)与为对手提供权限从而造成威胁的缺陷(称为攻击状态)相关联,并利用来自这些威胁的操作(称为攻击行为)。我们通过将其应用于两个案例研究来评估所提出的方法:(1)对文件检索的攻击,例如TOCTTOU攻击;(2)在进程之间传播的攻击,例如对Shell - shock漏洞的攻击。在这些案例研究中,我们展示了如何利用现有工具自动计算攻击图,并评估这些工具构建完整攻击图的有效性。虽然我们确定了一些研究领域,但我们也发现了攻击图能够为改进未来入侵检测系统提供有价值基础的几个原因。
Intrusion detection systems are a commonly deployed defense that examines network traffic, host operations, or both to detect attacks. However, more attacks bypass IDS defenses each year, and with the sophistication of attacks increasing as well, we must examine new perspectives for intrusion detection. Current intrusion detection systems focus on known attacks and/or vulnerabilities, limiting their ability to identify new attacks, and lack the visibility into all system components necessary to confirm attacks accurately, particularly programs. To change the landscape of intrusion detection, we propose that future IDSs track how attacks evolve across system layers by adapting the concept of attack graphs. Attack graphs were proposed to study how multi-stage attacks could be launched by exploiting known vulnerabilities. Instead of constructing attacks reactively, we propose to apply attack graphs proactively to detect sequences of events that fulfill the requirements for vulnerability exploitation. Using this insight, we examine how to generate modular attack graphs automatically that relate adversary accessibility for each component, called its attack surface, to flaws that provide adversaries with permissions that create threats, called attack states, and exploit operations from those threats, called attack actions. We evaluate the proposed approach by applying it to two case studies: (1) attacks on file retrieval, such as TOCTTOU attacks, and (2) attacks propagated among processes, such as attacks on Shell-shock vulnerabilities. In these case studies, we demonstrate how to leverage existing tools to compute attack graphs automatically and assess the effectiveness of these tools for building complete attack graphs. While we identify some research areas, we also find several reasons why attack graphs can provide a valuable foundation for improving future intrusion detection systems.