A Game-Theoretic Approach for Alert Prioritization

A Game-Theoretic Approach for Alert Prioritization
复制标题

警报优先级的博弈论方法

DOI:
--
复制
发表时间:
2017
期刊:
AAAI Workshops
影响因子:
--
通讯作者:
B. Malin
B. Malin
中科院分区:
--
文献类型:
--
作者:
Aron Laszka;Yevgeniy Vorobeychik;D. Fabbri;Chao Yan;B. Malin

文献摘要

被引文献

相似文献

计算机系统中收集和存储的信息量持续快速增长。同时,此类信息(例如详细的医疗记录)的敏感性通常使得此类信息对于可能通过破坏系统来获取信息的外部攻击者和可能通过行使授权滥用信息的恶意内部人员来说都很有价值。为了减少危害并阻止滥用,这些资源的安全管理员经常部署各种类型的入侵和滥用检测系统,这些系统提供值得后续审查的可疑事件警报。然而,在实践中,这些系统可能会产生大量误报,浪费调查人员的时间。鉴于安全管理员用于调查警报的预算有限,他们必须优先处理某些类型的警报。警报优先级划分的一个重要挑战是,对手可能会利用此类行为来逃避检测,特别是通过发起攻击来触发不太可能被调查的警报。在本文中,我们使用 Stackelberg 博弈对自适应对手的警报优先级进行建模,并介绍了一种计算警报类型的最佳优先级的方法。我们使用合成数据和由大型学术医疗中心使用的电子病历系统的审计日志生成的真实警报数据集来评估我们的方法。
The quantity of information that is collected and stored in computer systems continues to grow rapidly. At the same time, the sensitivity of such information (e.g., detailed medical records) often makes such information valuable to both external attackers, who may obtain information by compromising a system, and malicious insiders, who may misuse information by exercising their authorization. To mitigate compromises and deter misuse, the security administrators of these resources often deploy various types of intrusion and misuse detection systems, which provide alerts of suspicious events that are worthy of follow-up review. However, in practice, these systems may generate a large number of false alerts, wasting the time of investigators. Given that security administrators have limited budget for investigating alerts, they must prioritize certain types of alerts over others. An important challenge in alert prioritization is that adversaries may take advantage of such behavior to evade detection — specifically by mounting attacks that trigger alerts that are less likely to be investigated. In this paper, we model alert prioritization with adaptive adversaries using a Stackelberg game and introduce an approach to compute the optimal prioritization of alert types. We evaluate our approach using both synthetic data and a real-world dataset of alerts generated from the audit logs of an electronic medical record system in use at a large academic medical center.