Probabilistically Inferring Attack Ramifications Using Temporal Dependence Network

Probabilistically Inferring Attack Ramifications Using Temporal Dependence Network
复制标题

使用时间依赖网络概率推断攻击后果

DOI:
10.1109/tifs.2018.2833048
复制
发表时间:
2018-05
影响因子:
6.8
通讯作者:
Zhang Junjie
Zhang Junjie
中科院分区:
计算机科学1区
文献类型:
--
作者:
Yang Yuan;Cai Zhongmin;Wang Chunyan;Zhang Junjie

文献摘要

参考文献

相似文献

越来越需要评估和减轻成功攻击的影响。在被攻击的计算系统中发现恶意和受污染的对象被称为攻击分支的识别。以前的方法通过直接跟踪来自入侵根(即攻击的入口点)的信息流(或依赖)来识别攻击分支。它们面临着入侵根不确定和依赖爆炸等挑战。在本文中,我们提出了一种新的轻量级方法,能够在不知道入侵根源的情况下识别攻击分支,并且较少受到依赖爆炸的影响。该方法利用概率推理方法来融合从已知安全状态的对象子集中获得的证据。它首先将对象的生命周期划分为连续的时间片(对象片),以分析该对象的安全状态如何随时间变化。然后,根据对象片之间的信息流,从系统调用轨迹构建一个时间依赖网络(TDN)来关联对象片。在此基础上,建立了一个贝叶斯网络(BN)模型来表征感染在TDN中传播的不确定性。最后,该方法在BN模型上采用循环信念传播来推断对象的安全状态。我们使用389次攻击的大型数据集来评估所提出的方法,这些攻击是由真实世界的恶意软件样本发起的,包括像震网这样复杂的恶意软件。大量的实验表明,我们的方法能够在不知道入侵根源的情况下以97.47%的准确率和97.21%的召回率识别攻击分支。
There is an increasing need of assessing and mitigating the effects of successful attacks. Uncovering malicious and contaminated objects in an attacked computing system is referred to as identification of attack ramifications. Previous methods identify the attack ramifications by directly tracking information flows (or dependences) from the intrusion root (i.e., the entry point of an attack). They face challenges such as undetermined intrusion root and dependence explosion. In this paper, we present a novel, light-weight method capable of identifying attack ramifications without the knowledge of intrusion root and less subject to dependency explosion. The method utilizes a probabilistic reasoning approach to fuse evidence derived from a subset of objects whose security states are known. It first splits the lifetime of an object into consecutive time slices (object-slices) to profile how the security state of this object changes over time. Then, a temporal dependence network (TDN) is constructed from system call traces to correlate object-slices according to information flows between them. Based on that, a Bayesian network (BN) model is built to characterize the uncertainties of infection propagations in the TDN. Finally, the method adopts loopy belief propagation on the BN model to infer the security state of an object. We evaluate the proposed method using a large data set of 389 attacks launched by the real-world malware samples including sophisticated ones such as Stuxnet. Extensive experiments demonstrate that our method is able to identify attack ramifications with a 97.47% precision at 97.21% recall without the knowledge of intrusion root.
DOI: 10.1613/jair.5361
发表时间: 2015-07
期刊: J. Artif. Intell. Res.
影响因子: --
作者:
A. Motzek;R. Möller
通讯作者: A. Motzek;R. Möller
DOI: 10.1007/978-3-642-37300-8_9
发表时间: 2012-07
期刊: --
影响因子: --
作者:
Andrei Bacs;Remco Vermeulen;Asia Slowinska;H. Bos
通讯作者: Andrei Bacs;Remco Vermeulen;Asia Slowinska;H. Bos
DOI: 10.1145/2976749.2978378
发表时间: 2016-10
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Zhang Xu;Zhenyu Wu;Zhichun Li;Kangkook Jee;J. Rhee;Xusheng Xiao;Fengyuan Xu;Haining Wang;
通讯作者: Zhang Xu;Zhenyu Wu;Zhichun Li;Kangkook Jee;J. Rhee;Xusheng Xiao;Fengyuan Xu;Haining Wang;
DOI: 10.1109/iwia.2005.9
发表时间: 2005-03
期刊: Third IEEE International Workshop on Information Assurance (IWIA'05)
影响因子: --
作者:
Sriranjani Sitaraman;S. Venkatesan
通讯作者: Sriranjani Sitaraman;S. Venkatesan
DOI: 10.1109/tpds.2007.70765
发表时间: 2008-07
影响因子: 5.3
作者:
Xuxian Jiang;Florian P. Buchholz;Aaron Walters;Dongyan Xu;Yi-Min Wang;E. Spafford
通讯作者: Xuxian Jiang;Florian P. Buchholz;Aaron Walters;Dongyan Xu;Yi-Min Wang;E. Spafford