A Technology for Detection of Advanced Persistent Threat in Networks and Systems Using a Finite Angular State Velocity Machine and Vector Mathematics

A Technology for Detection of Advanced Persistent Threat in Networks and Systems Using a Finite Angular State Velocity Machine and Vector Mathematics
复制标题

使用有限角状态速度机和矢量数学检测网络和系统中的高级持续威胁的技术

DOI:
--
复制
发表时间:
2018
期刊:
Computer and Network Security Essentials
影响因子:
--
通讯作者:
Erica Bott
Erica Bott
中科院分区:
--
文献类型:
--
作者:
G. Vert;Ann Leslie Claesson;Jesse Roberts;Erica Bott

文献摘要

被引文献

相似文献

本章的目的是将高级日志发布状态机引擎应用于状态变量分析,以检测高级持续威胁(APT)和其他恶意软件的存在。有限角状态速度机(FAST-VM)可以对时间空间上的大量状态信息进行建模和分析。随着时间的推移对大量数据进行分析和建模的能力是检测高级持续性威胁的关键因素。在实验中,FAST-VM在大约24 ms内分析了10,000,000个状态变量向量。这表明了“大数据”在网络安全领域的应用。有限角状态转换速度机(FAST-VM)有能力解决这些挑战,并基于以前发表的Spicule工作。它将随着时间的推移而发生微妙变化的状态变量变化的高阶降低为易于理解的威胁分析,并且还可以预测未来的威胁。FAST-VM将IDS的三个主要领域(异常、误用和规范)统一到一个模型中。FAST-VM数学分析引擎在预测、分类和检测方面表现出了巨大的计算潜力,但它从未被映射到系统的状态变量。该技术寻求确定如何映射系统中的状态变量以检测APT。这一领域的成功技术开发可能会极大地影响计算的各个方面,特别是自动驾驶汽车和网络。本章将介绍这一先进技术的理论和应用。
The aim of this chapter is to apply an advanced journal-published state machine engine to the analysis of state variables that can detect the presence of Advanced Persistent Threat (APT) and other malware. The Finite Angular State Velocity Machine (FAST-VM) can model and analyze large amounts of state information over a temporal space. The ability to analyze and model large amounts of data over time is a key factor in detecting Advanced Persistent Threat. Experimentally, the FAST-VM has analyzed 10,000,000 state variable vectors in around 24 ms. This demonstrates the application of “big data” to the area of cyber security. The Finite Angular State Transition Velocity Machine (FAST-VM) has the capability to address these challenges and is based on previous published work with Spicule. It reduces the high order of state variable changes that have subtle changes in them over time to a threat analysis that is easy to comprehend and can also predict future threats. FAST-VM unifies the three major areas of IDS (anomaly, misuse, and specification) into a single model. The FAST-VM mathematical analysis engine has shown great computational possibilities in prediction, classification, and detection, but it has never been mapped to a system’s state variables. This technology seeks to determine how to map the state variables in a system to detect APT. Successful technology development in this area could dramatically affect all facets of computation, especially autonomous vehicles and networks. This chapter will present theory then application of this advanced technology.