Behavioral analytics for inferring large-scale orchestrated probing events

Behavioral analytics for inferring large-scale orchestrated probing events
复制标题

用于推断大规模精心策划的探测事件的行为分析

DOI:
10.1109/infcomw.2014.6849283
复制
发表时间:
2014
期刊:
2014 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS)
影响因子:
--
通讯作者:
C. Assi
C. Assi
中科院分区:
--
文献类型:
--
作者:
E. Bou;M. Debbabi;C. Assi

文献摘要

被引文献

相似文献

对网络空间的严重依赖确实带来了新的风险,这些风险往往损害、利用和破坏宝贵的数据和系统。因此,主动推断恶意活动的能力至关重要。在这种情况下,推断探测事件(通常是任何网络攻击的第一阶段)是实现这一任务的一种有希望的策略。在过去的三年里,我们每天都收到12 GB的恶意真实的暗网数据(即,目的地为50万个可路由但未分配的IP地址的互联网流量)。本文利用这些数据提出了一种新的方法,旨在捕获探测源的行为,试图推断它们的编排(即,协调)模式。后者定义了最近发现的一种新现象的特征,即探测事件可能被不祥地利用来造成巨大的互联网范围和企业影响,作为各种网络攻击的前兆。为了实现其目标,所提出的方法利用各种信号和统计技术,信息理论指标,模糊方法与真实的恶意软件流量和数据挖掘方法。该方法通过一个用例进行了验证,该用例可以证明,之前分析的去年的精心策划的探测事件确实仍然处于活动状态,但以隐身,非常低的速率模式运行。我们设想,针对暗网数据量身定制的所提出的方法可以被网络安全分析师、应急响应团队和/或网络事件观察员用于推断大规模精心策划的探测事件,以进行早期网络攻击预警和通知。
The significant dependence on cyberspace has indeed brought new risks that often compromise, exploit and damage invaluable data and systems. Thus, the capability to proactively infer malicious activities is of paramount importance. In this context, inferring probing events, which are commonly the first stage of any cyber attack, render a promising tactic to achieve that task. We have been receiving for the past three years 12 GB of daily malicious real darknet data (i.e., Internet traffic destined to half a million routable yet unallocated IP addresses) from more than 12 countries. This paper exploits such data to propose a novel approach that aims at capturing the behavior of the probing sources in an attempt to infer their orchestration (i.e., coordination) pattern. The latter defines a recently discovered characteristic of a new phenomenon of probing events that could be ominously leveraged to cause drastic Internet-wide and enterprise impacts as precursors of various cyber attacks. To accomplish its goals, the proposed approach leverages various signal and statistical techniques, information theoretical metrics, fuzzy approaches with real malware traffic and data mining methods. The approach is validated through one use case that arguably proves that a previously analyzed orchestrated probing event from last year is indeed still active, yet operating in a stealthy, very low rate mode. We envision that the proposed approach that is tailored towards darknet data, which is frequently, abundantly and effectively used to generate cyber threat intelligence, could be used by network security analysts, emergency response teams and/or observers of cyber events to infer large-scale orchestrated probing events for early cyber attack warning and notification.