High Fidelity Data Reduction for Big Data Security Dependency Analyses

High Fidelity Data Reduction for Big Data Security Dependency Analyses
复制标题

DOI:
10.1145/2976749.2978378
复制
发表时间:
2016-10
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Zhang Xu;Zhenyu Wu;Zhichun Li;Kangkook Jee;J. Rhee;Xusheng Xiao;Fengyuan Xu;Haining Wang;
Zhang Xu;Zhenyu Wu;Zhichun Li;Kangkook Jee;J. Rhee;Xusheng Xiao;Fengyuan Xu;Haining Wang;
中科院分区:
其他
文献类型:
--
作者:
Zhang Xu;Zhenyu Wu;Zhichun Li;Kangkook Jee;J. Rhee;Xusheng Xiao;Fengyuan Xu;Haining Wang;

文献摘要

被引文献

相似文献

入侵式多步骤攻击,如高级持续性威胁(APT)攻击,给企业带来了巨大的经济损失,也是企业增加安全预算的首要原因。由于这些攻击是复杂和隐蔽的,如果个别步骤被隐藏在背景噪音中,它们可以保持多年不被发现。因此,企业正在寻求解决方案,以便在多个活动中“连接可疑点”。这就需要长时间的无处不在的系统审计,这反过来又导致了大量的系统审计事件。在有限的系统预算下,如何有效地处理不断增加的系统审计日志是一个巨大的挑战。本文提出了一种新的方法,利用系统事件之间的依赖关系,以减少日志条目的数量,同时仍然支持高质量的取证分析。特别是,我们首先提出了一个聚合算法,保留依赖的事件在数据减少,以确保高质量的取证分析。然后,我们提出了一个积极的约简算法,并利用领域知识进一步减少数据。为了验证我们提出的方法的有效性,我们进行了全面的评估,对现实世界的审计系统使用日志跟踪超过一个月。我们的评估结果表明,我们的方法可以显着减少系统日志的大小,提高取证分析的效率,而不会失去准确性。
Intrusive multi-step attacks, such as Advanced Persistent Threat (APT) attacks, have plagued enterprises with significant financial losses and are the top reason for enterprises to increase their security budgets. Since these attacks are sophisticated and stealthy, they can remain undetected for years if individual steps are buried in background "noise." Thus, enterprises are seeking solutions to "connect the suspicious dots" across multiple activities. This requires ubiquitous system auditing for long periods of time, which in turn causes overwhelmingly large amount of system audit events. Given a limited system budget, how to efficiently handle ever-increasing system audit logs is a great challenge. This paper proposes a new approach that exploits the dependency among system events to reduce the number of log entries while still supporting high-quality forensic analysis. In particular, we first propose an aggregation algorithm that preserves the dependency of events during data reduction to ensure the high quality of forensic analysis. Then we propose an aggressive reduction algorithm and exploit domain knowledge for further data reduction. To validate the efficacy of our proposed approach, we conduct a comprehensive evaluation on real-world auditing systems using log traces of more than one month. Our evaluation results demonstrate that our approach can significantly reduce the size of system logs and improve the efficiency of forensic analysis without losing accuracy.