A novel kill-chain framework for remote security log analysis with SIEM software

A novel kill-chain framework for remote security log analysis with SIEM software
复制标题

DOI:
10.1016/j.cose.2017.03.003
复制
发表时间:
2017-06
期刊:
Comput. Secur.
影响因子:
--
通讯作者:
Blake D. Bryant;H. Saiedian
Blake D. Bryant;H. Saiedian
中科院分区:
其他
文献类型:
--
作者:
Blake D. Bryant;H. Saiedian

文献摘要

被引文献

相似文献

网络安全调查对试图确定安全警报或事件的根本原因的安全分析师提出了许多挑战。分析人员经常遇到这样的情况,要么是不完整的信息,要么是大量的信息以一种杂乱无章的方式呈现。这两种情况都会极大地影响事件响应者在安全事件发生时正确识别和响应的能力。本文提出的框架借鉴了先前关于带有杀伤链的网络威胁建模的研究,以及威胁建模在法医领域的实际应用。对传统杀伤链模型进行了修改,以促进关系数据库中的逻辑数据聚合,该数据库收集跨不同远程传感器的数据,从而为安全分析师提供更详细的警报。本文开发的框架被证明在识别安全警报之间的关系方面是有效的,它沿着一系列预期行为有利于以有系统的方式执行安全调查。该框架通过汇总有效地解决了不完整或不充分的报警信息,并提供了组织相关数据和进行标准调查的方法。事实证明,这两项改进都有助于以更迅速的方式有效识别安全威胁。
Network security investigations pose many challenges to security analysts attempting to identify the root cause of security alarms or incidents. Analysts are often presented with cases where either incomplete information is present, or an overwhelming amount of information is presented in a disorganized manner. Either scenario greatly impacts the ability for incident responders to properly identify and react to security incidents when they occur. The framework presented in this paper draws upon previous research pertaining to cyber threat modeling with kill-chains, as well as the practical application of threat modeling to forensic. Modifications were made to conventional kill-chain models to facilitate logical data aggregation within a relational database collecting data across disparate remote sensors resulting in more detailed alarms to security analysts. The framework developed in this paper proved effective in identifying the relationship of security alarms along a continuum of expected behaviors conducive to executing security investigations in a methodical manner. This framework effectively addressed incomplete or inadequate alarm information through aggregation, and provided a methodology for organizing related data and conducting standard investigations. Both improvements proved instrumental in the effective identification of security threats in a more expeditious manner.