课题基金 / 基金详情

Early Warning System for Data Exfiltration

Early Warning System for Data Exfiltration
数据泄露预警系统
批准号:
132833
负责人:
金额:
$8.92万
依托单位:
依托单位国家:
英国
项目类别:
Feasibility Studies
财政年份:
2017
资助国家:
英国
项目状态:
已结题
起止时间:
2017 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
网络安全监控需要一个预警系统。攻击变得越来越慢,越来越隐蔽,越来越复杂。安全漏洞的平均检测时间正在延长,导致被动防御和主动防御的错误平衡,并推高了安全和补救的总成本。现有的监控工具根本无法应对这种情况。总的来说,基于签名或规则的工具具有很强的追溯性。在一个特定的恶意软件通常只被使用很少几次的世界里,这种方法很快就会过时。相比之下,异常行为监测使防御者被误报所压倒,并努力处理预先感染的环境。有必要监测网络中与攻击早期阶段有关的指标的威胁概率。这是一种新的网络安全监控方法。这将使防御者能够在组织遭受数据丢失的巨大损失之前“将攻击扼杀在萌芽状态”,从而将优势转移回防御者手中。这种方法还可以对未知的攻击和漏洞进行警告;一种完全不同于基于事件后取证签名的方法。
英文摘要
Network security monitoring needs an early warning system. Attacks are getting slower, stealthier and more sophisticated. The average detection time of a security breach is lengthening, resulting in the wrong balance of reactive and proactive defence, and driving up the total cost of security and remediation. Existing monitoring tools will simply fail to cope with this. Broadly, the signature- or rule- based tools are very retrospective. This is quickly becoming obsolete, in a world where a specific malware is often only used a small handful of times. By contrast, anomalous behaviour monitoring overwhelms the defender with false positives and struggles to deal with pre-infected environments. There is a need to monitor networks for threat probabilities of indicators associated with early phases of attacks. This is a new approach to network security monitoring. It will shift the advantage back to the defender, by allowing them to “nip attacks in the bud”, before the organisation is exposed to significant costs of data loss. This approach also enables warning of unknown attacks and exploits; a fundamentally different approach to post-incident forensic signature-based methods.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金