Cardinality Change-based Early Detection of Large-scale Cyber-Attacks

被引:0
|
作者
Chen, Wenji [1 ]
Liu, Yang [1 ]
Guan, Yong [1 ]
机构
[1] Iowa State Univ, Dept Elect & Comp Engn, Ames, IA 50011 USA
关键词
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Cyber-attacks are happening every day, with a variety of behaviors and objects. For example, email spammers may compromise computers to sign-up millions of email accounts for sending spam emails; during worm spreading, each infected host may try to connect to many hosts to further spread the worm, etc. However, many such large-scale and often distributed cyber-attacks share a common characteristic that the activities involved in them result in changes in the cardinality of attack traffic. Examples include: the cardinality of the accounts signed up by a compromised host often increases in spam email delivery scenarios, and the cardinality of the connections made from a host may increase in worm spreading scenarios. In this paper, we focus on changes in the cardinality of the network/attack traffic that may indicate on-going cyber-attacks. We formulate this problem as cardinality-based change point detection in distributed streams of attack traffic, and develop a nonparametric error-bounded scheme for it. Our scheme supports the capability of merging information collected from multiple monitoring points to detect large-scale attacks. Also, our scheme uses small space as well as constant processing time, which makes it applicable for space-constrained network or security systems. We have conducted experiments using both real-world traces and synthetic data. Experimental results and theoretical analysis show that our scheme can detect changes in the cardinality within given time and error bounds. We expect the solutions of this work will be deployed as a building block in network and security monitoring systems to detect large distributed cyber attacks.
引用
收藏
页码:1788 / 1796
页数:9
相关论文
共 50 条
  • [1] On detectability of cyber-attacks for large-scale interconnected systems
    Gallo, Alexander J.
    Barboni, Angelo
    Parisini, Thomas
    [J]. IFAC PAPERSONLINE, 2020, 53 (02): : 3521 - 3526
  • [2] Fronesis: Digital Forensics-Based Early Detection of Ongoing Cyber-Attacks
    Dimitriadis, Athanasios
    Lontzetidis, Efstratios
    Kulvatunyou, Boonserm
    Ivezic, Nenad
    Gritzalis, Dimitris
    Mavridis, Ioannis
    [J]. IEEE ACCESS, 2023, 11 : 728 - 743
  • [3] Resilient State Estimation in Presence of Severe Coordinated Cyber-Attacks on Large-Scale Power Systems
    Jevtic, Ana
    Ilic, Marija
    [J]. 2020 IEEE POWER & ENERGY SOCIETY GENERAL MEETING (PESGM), 2020,
  • [4] Detection of Cyber-Attacks in Collaborative Intersection Control
    Keijzer, Twan
    Jarmolowitz, Fabian
    Ferrari, Riccardo M. G.
    [J]. 2021 EUROPEAN CONTROL CONFERENCE (ECC), 2021, : 62 - 67
  • [5] Cyber-Attacks Based in Electromagnetic Effects
    Perotoni, M. B.
    Barreto, R. M.
    Manfrin, S. K.
    [J]. IEEE LATIN AMERICA TRANSACTIONS, 2016, 14 (06) : 2838 - 2845
  • [6] Method of Early Detection of Cyber-Attacks on Telecommunication Networks Based on Traffic Analysis by Extreme Filtering
    Privalov, Andrey
    Lukicheva, Vera
    Kotenko, Igor
    Saenko, Igor
    [J]. ENERGIES, 2019, 12 (24)
  • [7] Detection of collaborative misbehaviour in distributed cyber-attacks
    Thoma, Marios
    Hadjicostis, Christoforos N.
    [J]. COMPUTER COMMUNICATIONS, 2021, 174 : 28 - 41
  • [8] Detection of Cyber-Attacks with Zone Dividing and PCA
    Morita, T.
    Yogo, S.
    Koike, M.
    Hamaguchi, T.
    Jung, S.
    Koshijima, I.
    Hashimoto, Y.
    [J]. 17TH INTERNATIONAL CONFERENCE IN KNOWLEDGE BASED AND INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS - KES2013, 2013, 22 : 727 - 736
  • [9] Detection of power grid disturbances and cyber-attacks based on machine learning
    Wang, Defu
    Wang, Xiaojuan
    Zhang, Yong
    Jin, Lei
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2019, 46 : 42 - 52
  • [10] Detection of Cyber-Attacks in a Discrete Event System Based on Deep Learning
    Ding, Sichen
    Liu, Gaiyun
    Yin, Li
    Wang, Jianzhou
    Li, Zhiwu
    [J]. MATHEMATICS, 2024, 12 (17)