Discovering Correlations: A Formal Definition of Causal Dependency Among Heterogeneous Events

被引:4
|
作者
Xosanavongsa, Charles [1 ]
Totel, Eric [2 ]
Bettan, Olivier [3 ]
机构
[1] Univ Rennes, INRIA, Cent Supelec, CNRS,IRISA,Thales Six GTS France, Rennes, France
[2] Univ Rennes, INRIA, Cent Supelec, CNRS,IRISA, Rennes, France
[3] Thales Six GTS France, Rennes, France
关键词
alert and event correlation; multi-step attack discovery; formal model; causal dependencies; distributed systems; forensic;
D O I
10.1109/EuroSP.2019.00033
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In order to supervise the security of a large infrastructure, the administrator deploys multiple sensors and intrusion detection systems on several critical places in the system. It is easier to explain and detect attacks if more events are logged. Starting from a suspicious event (appearing as a log entry), the administrator can start his investigation by manually building the set of previous events that are linked to this event of interest. Accordingly, the administrator attempts to identify links among the logged events in order to retrieve those that correspond to the traces of the attacker's actions in the supervised system; previous work is aimed at building these connections. In practice, however, this type of link is not trivial to define and discover. Hence, there is a real necessity to describe and define formally the semantics of these links in literature. In this paper, a clear definition of this relationship, called contextual event causal dependency, is introduced and proposed. The work presented in this paper aims at defining a formal model that would ideally unify previous work on causal dependencies among heterogeneous events. We define a relationship among events that enables the discovery of all events, which can be considered as the cause (in the past) or the effect (in the future) of an event of interest(e.g., an indicator of compromise, produced by an attacker action). This model is gradually introduced and defined by merging two previously defined causality models from the distributed system and operating system research areas (i.e., Lamport's and d'Ausbourg's). Our model takes into consideration heterogeneous events that emanate from different abstraction layers (e.g., network, system, and application) with the main objective of formally defining a causal relationship among logged events. Thereafter, we show how existing implementations separately allow the computation of parts of the model. Finally, we describe the implementation and assessment of the model according to real attacks on distributed environments and its accuracy to extract all causally linked events related to a given attack event trace.
引用
下载
收藏
页码:340 / 355
页数:16
相关论文
共 50 条
  • [31] Extracting Meaningful Correlations among Heterogeneous Datasets for Medical Question Answering with Domain Knowledge
    Feng, Jiayi
    Zhang, Runtong
    Chen, Donghua
    Zhang, Wei
    2018 IEEE 9TH ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2018, : 297 - 301
  • [32] CORRELATIONS BETWEEN HEARING THRESHOLDS AND CALORIC RESPONSES AMONG A HETEROGENEOUS SAMPLE OF DIZZY PATIENTS
    FORMBY, C
    HIXSONROBLES, C
    SINGLETON, GT
    JOURNAL OF SPEECH AND HEARING DISORDERS, 1988, 53 (01): : 65 - 70
  • [33] The revolution of congress meetings and scientific events: how to navigate among their heterogeneous modalities?
    Porpiglia, Francesco
    Amparore, Daniele
    Checcucci, Enrico
    Fiori, Cristian
    Artibani, Walter
    Scarpa, Roberto M.
    MINERVA UROLOGY AND NEPHROLOGY, 2021, 73 (01): : 3 - 5
  • [34] A theoretical formal model for mining transient events among databases of high energy astrophysics experiments
    Lazzarotto, F
    Feroci, M
    Pazienza, MT
    THIRD ROME WORKSHOP ON GAMMA-RAY BURSTS IN THE AFTERGLOW ERA, 2004, 312 : 528 - 531
  • [35] Heterogeneous correlations between hippocampus volume and cognitive map accuracy among healthy young adults
    He, Qiliang
    Brown, Thackery I.
    CORTEX, 2020, 124 : 167 - 175
  • [36] Principles of constructing a formal context-logical query constructor for accurate search of events in large arrays of heterogeneous information
    Farkhadov, Mais Pasha Ogly
    Pankratova, Ekaterina V.
    Blinova, Olga V.
    Smirnov, Valentin A.
    VESTNIK TOMSKOGO GOSUDARSTVENNOGO UNIVERSITETA-UPRAVLENIE VYCHISLITELNAJA TEHNIKA I INFORMATIKA-TOMSK STATE UNIVERSITY JOURNAL OF CONTROL AND COMPUTER SCIENCE, 2023, (64): : 138 - 145
  • [37] Inferring causal pathways among three or more variables from steady-state correlations in a homeostatic system
    Chawla, Suraj
    Pund, Anagha
    Vibishan, B.
    Kulkarni, Shubhankar
    Diwekar-Joshi, Manawa
    Watve, Milind
    PLOS ONE, 2018, 13 (10):
  • [38] STRESSFUL LIFE EVENTS, SOCIAL RHYTHMS, AND DEPRESSIVE SYMPTOMS AMONG THE ELDERLY - AN EXAMINATION OF HYPOTHESIZED CAUSAL LINKAGES
    PRIGERSON, HG
    REYNOLDS, CF
    FRANK, E
    KUPFER, DJ
    GEORGE, CJ
    HOUCK, PR
    PSYCHIATRY RESEARCH, 1994, 51 (01) : 33 - 49
  • [39] Heterogeneous Effects of Intensive Glycemic and Blood Pressure on Cardiovascular Events Among Diabetes by Living Arrangements
    Kiyohara, Kanta
    Kondo, Naoki
    Iwami, Taku
    Yano, Yuichiro
    Nishiyama, Akira
    Node, Koichi
    Inagaki, Nobuya
    Duru, O. Kenrik
    Inoue, Kosuke
    JOURNAL OF THE AMERICAN HEART ASSOCIATION, 2024, 13 (13): : e033860
  • [40] GAUCHER DISEASE - MOLECULAR HETEROGENEITY, FREQUENCY OF CAUSAL MUTATIONS, AND PHENOTYPE-GENOTYPE CORRELATIONS AMONG ETHNIC-GROUPS
    THEOPHILUS, B
    LATHAM, T
    GRABOWSKI, GA
    SMITH, FI
    PEDIATRIC RESEARCH, 1989, 25 (04) : A146 - A146