Data Exfiltration Detection and Prevention: Virtually Distributed POMDPs for Practically Safer Networks

被引:6
|
作者
Mc Carthy, Sara Marie [1 ]
Sinha, Arunesh [1 ]
Tambe, Milind [1 ]
Manadhata, Pratyusa [2 ]
机构
[1] Univ Southern Calif, Los Angeles, CA 90007 USA
[2] Hewlett Packard Labs, Princeton, NJ USA
关键词
COMPLEXITY;
D O I
10.1007/978-3-319-47413-7_3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We address the challenge of detecting and addressing advanced persistent threats (APTs) in a computer network, focusing in particular on the challenge of detecting data exfiltration over Domain Name System (DNS) queries, where existing detection sensors are imperfect and lead to noisy observations about the network's security state. Data exfiltration over DNS queries involves unauthorized transfer of sensitive data from an organization to a remote adversary through a DNS data tunnel to a malicious web domain. Given the noisy sensors, previous work has illustrated that standard approaches fail to satisfactorily rise to the challenge of detecting exfiltration attempts. Instead, we propose a decision-theoretic technique that sequentially plans to accumulate evidence under uncertainty while taking into account the cost of deploying such sensors. More specifically, we provide a fast scalable POMDP formulation to address the challenge, where the efficiency of the formulation is based on two key contributions: (i) we use a virtually distributed POMDP (VD-POMDP) formulation, motivated by previous work in distributed POMDPs with sparse interactions, where individual policies for different sub-POMDPs are planned separately but their sparse interactions are only resolved at execution time to determine the joint actions to perform; (ii) we allow for abstraction in planning for speedups, and then use a fast MILP to implement the abstraction while resolving any interactions. This allows us to determine optimal sensing strategies, leveraging information from many noisy detectors, and subject to constraints imposed by network topology, forwarding rules and performance costs on the frequency, scope and efficiency of sensing we can perform.
引用
收藏
页码:39 / 61
页数:23
相关论文
共 38 条
  • [1] Data detection in decentralized and distributed massive MIMO networks
    Albreem, Mahmoud A.
    Alhabbash, Alaa
    Abu-Hudrouss, Ammar M.
    Almohamad, Tarik Adnan
    [J]. COMPUTER COMMUNICATIONS, 2022, 189 : 79 - 99
  • [2] A distributed detection and prevention scheme from malicious nodes in vehicular networks
    Bouali, Tarek
    Senouci, Sidi-Mohammed
    Sedjelmaci, Hichem
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2016, 29 (10) : 1683 - 1704
  • [3] Bayesian Data Fusion for Distributed Target Detection in Sensor Networks
    Guerriero, Marco
    Svensson, Lennart
    Willett, Peter
    [J]. IEEE TRANSACTIONS ON SIGNAL PROCESSING, 2010, 58 (06) : 3417 - 3421
  • [4] Distributed Data-theft Detection in Wireless Sensor Networks
    Jagasia, Mukesh
    Huang, Dijiang
    [J]. GLOBECOM 2009 - 2009 IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-8, 2009, : 5729 - 5734
  • [5] A Flow-based Multi-agent Data Exfiltration Detection Architecture for Ultra-low Latency Networks
    Marques, Rafael Salema
    Epiphaniou, Gregory
    Al-Khateeb, Haider
    Maple, Carsten
    Hammoudeh, Mohammad
    De Castro, Paulo Andre Lima
    Dehghantanha, Ali
    Choo, Kkwang Raymond
    [J]. ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2021, 21 (04)
  • [6] A Distributed Bayesian Algorithm for Data Fault Detection in Wireless Sensor Networks
    Yuan, Hao
    Zhao, Xiaoxia
    Yu, Liyang
    [J]. 2015 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2015, : 63 - 68
  • [7] A distributed method for state estimation and false data detection in power networks
    Pasqualetti, Fabio
    Carli, Ruggero
    Bullo, Francesco
    [J]. 2011 IEEE INTERNATIONAL CONFERENCE ON SMART GRID COMMUNICATIONS (SMARTGRIDCOMM), 2011,
  • [8] A data mining system for distributed abnormal event detection in backbone networks
    Zhou, Yingjie
    Hu, Guangmin
    Wu, Dapeng
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (05) : 904 - 913
  • [9] A data-centric distributed detection scheme in wireless sensor networks
    Zhang, Yuan
    Sun, Runyuan
    Yang, Bo
    [J]. 2006 1ST INTERNATIONAL SYMPOSIUM ON PERVASIVE COMPUTING AND APPLICATIONS, PROCEEDINGS, 2006, : 699 - +
  • [10] Distributed computing and big data techniques for efficient fault detection and data management in wireless networks
    Ajmeera Kiran
    P. N. Renjith
    Sapna Gupta
    Srinivas Ambala
    Preethi Sambandam Raju
    Drakshayani Sriramsetti
    [J]. Optical and Quantum Electronics, 2023, 55