Discovering Correlations: A Formal Definition of Causal Dependency Among Heterogeneous Events

被引:4
|
作者
Xosanavongsa, Charles [1 ]
Totel, Eric [2 ]
Bettan, Olivier [3 ]
机构
[1] Univ Rennes, INRIA, Cent Supelec, CNRS,IRISA,Thales Six GTS France, Rennes, France
[2] Univ Rennes, INRIA, Cent Supelec, CNRS,IRISA, Rennes, France
[3] Thales Six GTS France, Rennes, France
关键词
alert and event correlation; multi-step attack discovery; formal model; causal dependencies; distributed systems; forensic;
D O I
10.1109/EuroSP.2019.00033
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In order to supervise the security of a large infrastructure, the administrator deploys multiple sensors and intrusion detection systems on several critical places in the system. It is easier to explain and detect attacks if more events are logged. Starting from a suspicious event (appearing as a log entry), the administrator can start his investigation by manually building the set of previous events that are linked to this event of interest. Accordingly, the administrator attempts to identify links among the logged events in order to retrieve those that correspond to the traces of the attacker's actions in the supervised system; previous work is aimed at building these connections. In practice, however, this type of link is not trivial to define and discover. Hence, there is a real necessity to describe and define formally the semantics of these links in literature. In this paper, a clear definition of this relationship, called contextual event causal dependency, is introduced and proposed. The work presented in this paper aims at defining a formal model that would ideally unify previous work on causal dependencies among heterogeneous events. We define a relationship among events that enables the discovery of all events, which can be considered as the cause (in the past) or the effect (in the future) of an event of interest(e.g., an indicator of compromise, produced by an attacker action). This model is gradually introduced and defined by merging two previously defined causality models from the distributed system and operating system research areas (i.e., Lamport's and d'Ausbourg's). Our model takes into consideration heterogeneous events that emanate from different abstraction layers (e.g., network, system, and application) with the main objective of formally defining a causal relationship among logged events. Thereafter, we show how existing implementations separately allow the computation of parts of the model. Finally, we describe the implementation and assessment of the model according to real attacks on distributed environments and its accuracy to extract all causally linked events related to a given attack event trace.
引用
下载
收藏
页码:340 / 355
页数:16
相关论文
共 50 条
  • [21] The effect of temporal information among events on Bayesian causal inference in rats
    Sawa, Kosuke
    Kurihara, Akira
    FRONTIERS IN PSYCHOLOGY, 2014, 5
  • [22] Extracting Causal Relations Among Complex Events in Natural Science Literature
    Barik, Biswanath
    Marsi, Erwin
    Ozturk, Pinar
    NATURAL LANGUAGE PROCESSING AND INFORMATION SYSTEMS, NLDB 2017, 2017, 10260 : 131 - 137
  • [23] Discovering Co-occurrence Patterns of Heterogeneous Events from Unevenly-distributed Spatiotemporal Data
    Hung Tran-The
    Zettsu, Koji
    2017 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2017, : 1006 - 1011
  • [24] Discovering and understanding multi-dimensional correlations among certification requirements with application to risk assessment
    Gandhi, Robin A.
    Lee, Seok-Won
    15TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE, PROCEEDINGS, 2007, : 231 - +
  • [25] Beyond the definition of formal care: Informal care arrangements among older swedes who are not family
    Siira, Elfin
    Rolandsson, Bertil
    Wijk, Helle
    Wolf, Axel
    HEALTH & SOCIAL CARE IN THE COMMUNITY, 2020, 28 (02) : 633 - 641
  • [26] The Causal Nexus Among Energy Dependency, Human Capital, and Renewable Energy: An Empirical Analysis for EU Members
    Sart, Gamze
    Özekicioğlu, Halil
    Danilina, Marina
    Aytemiz, Levent
    Bayar, Yilmaz
    Energies, 2024, 17 (21)
  • [27] Reducing Local Correlations Among Causal Factor Classifications as a Strategy to Improve Landslide Susceptibility Mapping
    Xiao, Ting
    Yu, Lanbing
    Tian, Weiming
    Zhou, Chang
    Wang, Luqi
    FRONTIERS IN EARTH SCIENCE, 2021, 9
  • [28] The development of reasoning about the temporal and causal relations among past, present, and future events
    Lohse, Karoline
    Kalitschke, Theresa
    Ruthmann, Katja
    Rakoczy, Hannes
    JOURNAL OF EXPERIMENTAL CHILD PSYCHOLOGY, 2015, 138 : 54 - 70
  • [29] ChatGPT and Academic Writing Self-Efficacy: Unveiling Correlations and Technological Dependency among Postgraduate Students
    Bouzar, Abdelouahd
    Idrissi, Khaoula E. L.
    Ghourdou, Tayeb
    ARAB WORLD ENGLISH JOURNAL, 2024, : 225 - 236
  • [30] Differences in the Use of Formal and Informal Care Services among Older Adults after the Implementation of the Dependency Act in Spain*
    Cantarero Prieto, David
    Pascual, Marta
    Rodriguez-Sanchez, Beatriz
    HACIENDA PUBLICA ESPANOLA-REVIEW OF PUBLIC ECONOMICS, 2022, 240 : 61 - 93