A Novel AI-based Methodology for Identifying Cyber Attacks in Honey Pots

A Novel AI-based Methodology for Identifying Cyber Attacks in Honey Pots
复制标题

DOI:
10.1609/aaai.v35i17.17786
复制
发表时间:
2021-05
期刊:
--
影响因子:
--
通讯作者:
Muhammed AbuOdeh;Christian Adkins;Omid Setayeshfar;Prashant Doshi;K. H. Lee
Muhammed AbuOdeh;Christian Adkins;Omid Setayeshfar;Prashant Doshi;K. H. Lee
中科院分区:
其他
文献类型:
--
作者:
Muhammed AbuOdeh;Christian Adkins;Omid Setayeshfar;Prashant Doshi;K. H. Lee

文献摘要

相似文献

我们提出了一种新的基于AI的方法,可以简单地从系统调用日志中识别主机级网络攻击的阶段。来自主机上的网络攻击(如蜜罐)的系统调用通常记录在审计日志中。我们的方法首先涉及有效地加载,缓存,处理和查询系统事件中包含的审计日志,以支持计算机取证。查询的输出仍停留在系统调用级别,难以处理。下一步是从作为观测值给出的系统调用中推断出一系列抽象的操作,我们通俗地称之为故事情节。这些故事情节,然后准确地识别类标签使用学习分类。我们定性和定量地评估方法和模型的每一个步骤的方法,使用114个不同的攻击阶段,通过记录一个红队在服务器上的攻击,在一些可能的良性序列包含定期用户活动,并从最近的DARPA项目的痕迹收集。由此产生的端到端系统,我们称之为Cyberian,以高精度识别攻击阶段,说明这种基于机器学习的方法为安全取证带来的好处。
We present a novel AI-based methodology that identifies phases of a host-level cyber attack simply from system call logs. System calls emanating from cyber attacks on hosts such as honey pots are often recorded in audit logs. Our methodology first involves efficiently loading, caching, processing, and querying system events contained in audit logs in support of computer forensics. Output of queries remains at the system call level and is difficult to process. The next step is to infer a sequence of abstracted actions, which we colloquially call a storyline, from the system calls given as observations to a latent-state probabilistic model. These storylines are then accurately identified with class labels using a learned classifier. We qualitatively and quantitatively evaluate methods and models for each step of the methodology using 114 different attack phases collected by logging the attacks of a red team on a server, on some likely benign sequences containing regular user activities, and on traces from a recent DARPA project. The resulting end-to-end system, which we call Cyberian, identifies the attack phases with a high level of accuracy illustrating the benefit that this machine learning-based methodology brings to security forensics.