Discovering Correlations: A Formal Definition of Causal Dependency Among Heterogeneous Events

被引:4
|
作者
Xosanavongsa, Charles [1 ]
Totel, Eric [2 ]
Bettan, Olivier [3 ]
机构
[1] Univ Rennes, INRIA, Cent Supelec, CNRS,IRISA,Thales Six GTS France, Rennes, France
[2] Univ Rennes, INRIA, Cent Supelec, CNRS,IRISA, Rennes, France
[3] Thales Six GTS France, Rennes, France
关键词
alert and event correlation; multi-step attack discovery; formal model; causal dependencies; distributed systems; forensic;
D O I
10.1109/EuroSP.2019.00033
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In order to supervise the security of a large infrastructure, the administrator deploys multiple sensors and intrusion detection systems on several critical places in the system. It is easier to explain and detect attacks if more events are logged. Starting from a suspicious event (appearing as a log entry), the administrator can start his investigation by manually building the set of previous events that are linked to this event of interest. Accordingly, the administrator attempts to identify links among the logged events in order to retrieve those that correspond to the traces of the attacker's actions in the supervised system; previous work is aimed at building these connections. In practice, however, this type of link is not trivial to define and discover. Hence, there is a real necessity to describe and define formally the semantics of these links in literature. In this paper, a clear definition of this relationship, called contextual event causal dependency, is introduced and proposed. The work presented in this paper aims at defining a formal model that would ideally unify previous work on causal dependencies among heterogeneous events. We define a relationship among events that enables the discovery of all events, which can be considered as the cause (in the past) or the effect (in the future) of an event of interest(e.g., an indicator of compromise, produced by an attacker action). This model is gradually introduced and defined by merging two previously defined causality models from the distributed system and operating system research areas (i.e., Lamport's and d'Ausbourg's). Our model takes into consideration heterogeneous events that emanate from different abstraction layers (e.g., network, system, and application) with the main objective of formally defining a causal relationship among logged events. Thereafter, we show how existing implementations separately allow the computation of parts of the model. Finally, we describe the implementation and assessment of the model according to real attacks on distributed environments and its accuracy to extract all causally linked events related to a given attack event trace.
引用
收藏
页码:340 / 355
页数:16
相关论文
共 50 条
  • [41] Correlations between negative life events and suicidal ideation among Chinese adolescents: a meta-analysis
    He, Xubin
    Yang, Ping
    Yu, Qinyao
    Yang, Bo
    FRONTIERS IN PSYCHIATRY, 2023, 14
  • [42] Centro Events and Causal Connections: A Narrative-Inquiry Study among Colombian Female Scholars in their Processes as Writers
    Ramos-Holguin, Bertha
    Carolina Penaloza-Rallon, Anna
    GIST-EDUCATION AND LEARNING RESEARCH JOURNAL, 2020, (20): : 33 - 63
  • [43] Causal interactions and financial contagion among the BRICS stock markets under rare events: a Liang causality analysis
    Lu, Xunfa
    Sun, Jingjing
    Wei, Guo
    Chang, Ching-Ter
    INTERNATIONAL JOURNAL OF EMERGING MARKETS, 2023,
  • [44] Using k-dependence causal forest to mine the most significant dependency relationships among clinical variables for thyroid disease diagnosis
    Wang, LiMin
    Cao, FangYuan
    Wang, ShuangCheng
    Sun, MingHui
    Dong, LiYan
    PLOS ONE, 2017, 12 (08):
  • [45] Negative life events, depression, and mobile phone dependency among left-behind adolescents in rural China: An interpersonal perspective
    Zhen, Rui
    Li, Lu
    Liu, Xuanwen
    Zhou, Xiao
    CHILDREN AND YOUTH SERVICES REVIEW, 2020, 109
  • [46] Revealing heterogeneous causal links among financial development, construction industry, energy use, and environmental quality across development levels
    Ahmad, Munir
    Jabeen, Gul
    Hayat, Muhammad Khizar
    Khan, Rana Ejaz Ali
    Qamar, Shoaib
    ENVIRONMENTAL SCIENCE AND POLLUTION RESEARCH, 2020, 27 (05) : 4976 - 4996
  • [47] Revealing heterogeneous causal links among financial development, construction industry, energy use, and environmental quality across development levels
    Munir Ahmad
    Gul Jabeen
    Muhammad Khizar Hayat
    Rana Ejaz Ali Khan
    Shoaib Qamar
    Environmental Science and Pollution Research, 2020, 27 : 4976 - 4996
  • [48] Survey on digital dependency, writing by hand, and group learning as learning styles among Japanese medical students: Assessing correlations between various accomplishments
    Komasawa, Nobuyasu
    Takitani, Kimitaka
    Lee, Sang-Woong
    Terasaki, Fumio
    Nakano, Takashi
    JOURNAL OF EDUCATION AND HEALTH PROMOTION, 2023, 12 (01) : 204
  • [49] Cross-cultural universality and variation of causal attribution: A comparative study of attribution of social events among Chinese, Korean and American
    Wu Shengtao
    Zhang Jianxin
    Lai Jianwei
    INTERNATIONAL JOURNAL OF PSYCHOLOGY, 2008, 43 (3-4) : 598 - 599
  • [50] Estimating the Heterogeneous Causal Effects of Parent-Child Relationships among Chinese Children with Oppositional Defiant Symptoms: A Machine Learning Approach
    Zhou, Haiyan
    Han, Fengkai
    Chen, Ruoxi
    Huang, Jiajin
    Chen, Jianhui
    Lin, Xiuyun
    BEHAVIORAL SCIENCES, 2024, 14 (06)