Multi-Stage Attack Detection Using Contextual Information

被引:0
|
作者
Aparicio-Navarro, Francisco J. [1 ]
Kyriakopoulos, Konstantinos G. [2 ,3 ]
Ghafir, Ibrahim [2 ]
Lambotharan, Sangarapillai [2 ]
Chambers, Jonathon A. [4 ]
机构
[1] De Montfort Univ, Fac Technol, Leicester LE1 9BH, Leics, England
[2] Loughborough Univ, Wolfson Sch Engn, Loughborough LE11 3TU, Leics, England
[3] Loughborough Univ London, Inst Digital Technol, London E15 2GZ, England
[4] Newcastle Univ, Sch Engn, Newcastle Upon Tyne NE1 7RU, Tyne & Wear, England
基金
英国工程与自然科学研究理事会;
关键词
Contextual Information; Dempster-Shafer Theory; Fuzzy Cognitive Maps; Intrusion Detection System; Multi-Stage Attack; Network Security; Pattern-of-Life; Point of Entry;
D O I
暂无
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
The appearance of new forms of cyber-threats, such as Multi-Stage Attacks (MSAs), creates new challenges to which Intrusion Detection Systems (IDSs) need to adapt. An MSA is launched in multiple sequential stages, which may not be malicious when implemented individually, making the detection of MSAs extremely challenging for most current IDSs. In this paper, we present a novel IDS that exploits contextual information in the form of Pattern-of-Life (PoL), and information related to expert judgment on the network behaviour. This IDS focuses on detecting an MSA, in real-time, without previous training process. The main goal of the MSA is to create a Point of Entry (PoE) to a target machine, which could be used as part of an Advanced Persistent Threat (APT) like attack. Our results verify that the use of contextual information improves the efficiency of our IDS by enhancing the detection rate of MSAs in real-time by 58%.
引用
下载
收藏
页码:932 / 937
页数:6
相关论文
共 50 条
  • [41] Information aggregation in a large multi-stage market game
    Hu, Tai-Wei
    Wallace, Neil
    JOURNAL OF ECONOMIC THEORY, 2016, 161 : 103 - 144
  • [42] Predicting Multi-Stage Attacks Based on IP Information
    Almutairi, Abdulrazaq
    Parish, David
    Flint, James
    2015 10TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2015, : 384 - 390
  • [43] Multi-stage Dynamic Information Flow Tracking Game
    Moothedath, Shana
    Sahabandu, Dinuka
    Clark, Andrew
    Lee, Sangho
    Lee, Wenke
    Poovendran, Radha
    DECISION AND GAME THEORY FOR SECURITY, GAMESEC 2018, 2018, 11199 : 80 - 101
  • [44] Model of Information Multi-Stage Process in Structured System
    Malafeyev, Oleg
    Redinskikh, Nadezhda
    Zaitseva, Irina
    Smirnova, Tatiana
    Kolesov, Dmitry
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE OF COMPUTATIONAL METHODS IN SCIENCES AND ENGINEERING 2019 (ICCMSE-2019), 2019, 2186
  • [45] An Enhanced Multi-Stage Semantic Attack Against Industrial Control Systems
    Hu, Yan
    Sun, Yuyan
    Wang, Youcheng
    Wang, Zhiliang
    IEEE ACCESS, 2019, 7 : 156871 - 156882
  • [46] Multi-Stage Salient Object Detection in 360° Omnidirectional Image Using Complementary Object-Level Semantic Information
    Chen, Gang
    Shao, Feng
    Chai, Xiongli
    Jiang, Qiuping
    Ho, Yo-Sung
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTATIONAL INTELLIGENCE, 2024, 8 (01): : 776 - 789
  • [47] Modeling for heterogeneous multi-stage information propagation networks and maximizing information
    梅人杰
    丁李
    安栩明
    胡萍
    Chinese Physics B, 2019, 28 (02) : 454 - 463
  • [48] Modeling for heterogeneous multi-stage information propagation networks and maximizing information
    Mei, Ren-Jie
    Ding, Li
    An, Xu-Ming
    Hu, Ping
    CHINESE PHYSICS B, 2019, 28 (02)
  • [49] A Vehicle Detection Using Selective Multi-stage Features in Convolutional Neural Networks
    Lee, Won Jae
    Pae, Dong Sung
    Kim, Dong Won
    Lim, Myo Taeg
    2017 17TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION AND SYSTEMS (ICCAS), 2017, : 1 - 3
  • [50] Evaluation of Abnormal Sound Detection using Multi-stage GMM in Various Environments
    Ito, Akinori
    Aiba, Akihito
    Ito, Masashi
    Makino, Shozo
    12TH ANNUAL CONFERENCE OF THE INTERNATIONAL SPEECH COMMUNICATION ASSOCIATION 2011 (INTERSPEECH 2011), VOLS 1-5, 2011, : 308 - +