Topology-based Host-Level Attribution for Multi-Stage Attacks in Enterprise Systems using Software Defined Networks
Topology-based Host-Level Attribution for Multi-Stage Attacks in Enterprise Systems using Software Defined Networks
复制标题
使用软件定义网络对企业系统中的多阶段攻击进行基于拓扑的主机级归因
DOI:
10.1007/978-3-319-78813-5_36
复制
发表时间:
2018
期刊:
影响因子:
--
通讯作者:
Bagchi, S
中科院分区:
文献类型:
--
作者:
Kannan, S;Wood, P;Deatrick, L;Beane, P;Chaterji, S;Bagchi, S
Multi-layer distributed systems, such as those found in corporate systems, are often the target of multi-stage attacks. Such attacks utilize multiple victim machines, in a series, to compromise a target asset deep inside the corporate network. Under such attacks, it is difficult to identify the upstream attacker’s identity from a downstream victim machine because of the mixing of multiple network flows. This is known as the attribution problem in security domains. We presentTopHat, a system that solves such attribution problems for multi-stage attacks. It does this by using moving target defense,i.e., shuffling the assignment of clients to server replicas, which is achieved through software defined networking. As alerts are generated,TopHatmaintains state about the level of risk for each network flow and progressively isolates the malicious flows. Using a simulation, we show thatTopHatcan identify single and multiple attackers in a variety of systems with different numbers of servers, layers, and clients.