Topology-based Host-Level Attribution for Multi-Stage Attacks in Enterprise Systems using Software Defined Networks

Topology-based Host-Level Attribution for Multi-Stage Attacks in Enterprise Systems using Software Defined Networks
复制标题

使用软件定义网络对企业系统中的多阶段攻击进行基于拓扑的主机级归因

DOI:
10.1007/978-3-319-78813-5_36
复制
发表时间:
2018
期刊:
Social Informatics and Telecommunications Engineering
影响因子:
--
通讯作者:
Bagchi, S
Bagchi, S
中科院分区:
--
文献类型:
--
作者:
Kannan, S;Wood, P;Deatrick, L;Beane, P;Chaterji, S;Bagchi, S

文献摘要

相似文献

多层分布式系统,例如在公司系统中发现的系统,通常是多阶段攻击的目标。这种攻击利用多台受害者机器,在一系列中,危害公司网络深处的目标资产。在这种攻击下,由于多个网络流的混合,很难从下游受害机器识别上游攻击者的身份。这被称为安全域中的属性问题。我们presentTopHat,一个系统,解决了这种归属问题的多阶段攻击。它通过使用移动目标防御来做到这一点,即,将客户端的分配混洗到服务器副本,这是通过软件定义的网络实现的。在生成警报时,TopHat会维护每个网络流的风险级别状态,并逐步隔离恶意流。使用模拟,我们表明,TopHat可以识别单个和多个攻击者在各种系统中的不同数量的服务器,层和客户端。
Multi-layer distributed systems, such as those found in corporate systems, are often the target of multi-stage attacks. Such attacks utilize multiple victim machines, in a series, to compromise a target asset deep inside the corporate network. Under such attacks, it is difficult to identify the upstream attacker’s identity from a downstream victim machine because of the mixing of multiple network flows. This is known as the attribution problem in security domains. We presentTopHat, a system that solves such attribution problems for multi-stage attacks. It does this by using moving target defense,i.e., shuffling the assignment of clients to server replicas, which is achieved through software defined networking. As alerts are generated,TopHatmaintains state about the level of risk for each network flow and progressively isolates the malicious flows. Using a simulation, we show thatTopHatcan identify single and multiple attackers in a variety of systems with different numbers of servers, layers, and clients.