Multi-Stage Attack Detection Using Contextual Information

被引:0
|
作者
Aparicio-Navarro, Francisco J. [1 ]
Kyriakopoulos, Konstantinos G. [2 ,3 ]
Ghafir, Ibrahim [2 ]
Lambotharan, Sangarapillai [2 ]
Chambers, Jonathon A. [4 ]
机构
[1] De Montfort Univ, Fac Technol, Leicester LE1 9BH, Leics, England
[2] Loughborough Univ, Wolfson Sch Engn, Loughborough LE11 3TU, Leics, England
[3] Loughborough Univ London, Inst Digital Technol, London E15 2GZ, England
[4] Newcastle Univ, Sch Engn, Newcastle Upon Tyne NE1 7RU, Tyne & Wear, England
基金
英国工程与自然科学研究理事会;
关键词
Contextual Information; Dempster-Shafer Theory; Fuzzy Cognitive Maps; Intrusion Detection System; Multi-Stage Attack; Network Security; Pattern-of-Life; Point of Entry;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The appearance of new forms of cyber-threats, such as Multi-Stage Attacks (MSAs), creates new challenges to which Intrusion Detection Systems (IDSs) need to adapt. An MSA is launched in multiple sequential stages, which may not be malicious when implemented individually, making the detection of MSAs extremely challenging for most current IDSs. In this paper, we present a novel IDS that exploits contextual information in the form of Pattern-of-Life (PoL), and information related to expert judgment on the network behaviour. This IDS focuses on detecting an MSA, in real-time, without previous training process. The main goal of the MSA is to create a Point of Entry (PoE) to a target machine, which could be used as part of an Advanced Persistent Threat (APT) like attack. Our results verify that the use of contextual information improves the efficiency of our IDS by enhancing the detection rate of MSAs in real-time by 58%.
引用
收藏
页码:932 / 937
页数:6
相关论文
共 50 条
  • [1] A Framework for Multi-stage Attack Detection
    Alserhani, Faeiz
    [J]. 2013 SAUDI INTERNATIONAL ELECTRONICS, COMMUNICATIONS AND PHOTONICS CONFERENCE (SIECPC), 2013,
  • [2] Addressing Multi-Stage Attacks Using Expert Knowledge and Contextual Information
    Aparicio-Navarro, Francisco J.
    Chadza, Timothy A.
    Kyriakopoulos, Konstantinos G.
    Ghafir, Ibrahim
    Lambotharan, Sangarapillai
    AsSadhan, Basil
    [J]. PROCEEDINGS OF THE 2019 22ND CONFERENCE ON INNOVATION IN CLOUDS, INTERNET AND NETWORKS AND WORKSHOPS (ICIN), 2019, : 188 - 194
  • [3] Multi-Stage Contextual Deep Learning for Pedestrian Detection
    Zeng, Xingyu
    Ouyang, Wanli
    Wang, Xiaogang
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2013, : 121 - 128
  • [4] Anomaly based multi-stage attack detection method
    Ma, Wei
    Hou, Yunyun
    Jin, Mingyu
    Jian, Pengpeng
    [J]. PLOS ONE, 2024, 19 (03): : 1 - 20
  • [5] Multi-stage Attack Detection and Signature Generation with ICS Honeypots
    Vasilomanolakis, Emmanouil
    Srinivasa, Shreyas
    Cordero, Carlos Garcia
    Muhlhauser, Max
    [J]. NOMS 2016 - 2016 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2016, : 1227 - 1232
  • [6] APT-Attack Detection Based on Multi-Stage Autoencoders
    Neuschmied, Helmut
    Winter, Martin
    Stojanovic, Branka
    Hofer-Schmitz, Katharina
    Bozic, Josip
    Kleb, Ulrike
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (13):
  • [7] A Multi-stage APT Attack Detection Method Based on Sample Enhancement
    Xie, Lixia
    Li, Xueou
    Yang, Hongyu
    Zhang, Liang
    [J]. CYBERSPACE SAFETY AND SECURITY, CSS 2022, 2022, 13547 : 209 - 216
  • [8] Multi-stage detection using constellation structure
    Sen Gupta, Ananya
    Singer, Andrew C.
    [J]. 2006 FORTIETH ASILOMAR CONFERENCE ON SIGNALS, SYSTEMS AND COMPUTERS, VOLS 1-5, 2006, : 585 - +
  • [9] Improved Detection and Correlation of Multi-Stage VoIP Attack Patterns by using a Dynamic Honeynet System
    Hoffstadt, Dirk
    Wolff, Niels
    Monhof, Stefan
    Rathgeb, Erwin
    [J]. 2013 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2013,
  • [10] Towards an Approach to Contextual Detection of Multi-Stage Cyber Attacks in Smart Grids
    Sen, Oemer
    van der Velde, Dennis
    Wehrmeister, Katharina A.
    Hacker, Immanuel
    Henze, Martin
    Andres, Michael
    [J]. 2021 INTERNATIONAL CONFERENCE ON SMART ENERGY SYSTEMS AND TECHNOLOGIES (SEST), 2021,