Big knowledge-based semantic correlation for detecting slow and low-level advanced persistent threats

被引:3
|
作者
Lajevardi, Amir Mohammadzade [1 ]
Amini, Morteza [1 ]
机构
[1] Sharif Univ Technol, Dept Comp Engn, Tehran, Iran
基金
美国国家科学基金会;
关键词
Advanced persistent threat; Big semantic correlation; Ontology; Intrusion detection; INTRUSION DETECTION SYSTEM; ATTACK; BEHAVIOR; IDS;
D O I
10.1186/s40537-021-00532-9
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Targeted cyber attacks, which today are known as Advanced Persistent Threats (APTs), use low and slow patterns to bypass intrusion detection and alert correlation systems. Since most of the attack detection approaches use a short time-window, the slow APTs abuse this weakness to escape from the detection systems. In these situations, the intruders increase the time of attacks and move as slowly as possible by some tricks such as using sleeper and wake up functions and make detection difficult for such detection systems. In addition, low APTs use trusted subjects or agents to conceal any footprint and abnormalities in the victim system by some tricks such as code injection and stealing digital certificates. In this paper, a new solution is proposed for detecting both low and slow APTs. The proposed approach uses low-level interception, knowledge-based system, system ontology, and semantic correlation to detect low-level attacks. Since using semantic-based correlation is not applicable for detecting slow attacks due to its significant processing overhead, we propose a scalable knowledge-based system that uses three different concepts and approaches to reduce the time complexity including (1) flexible sliding window called Vermiform window to analyze and correlate system events instead of using fixed-size time-window, (2) effective inference using a scalable inference engine called SANSA, and (3) data reduction by ontology-based data abstraction. We can detect the slow APTs whose attack duration is about several months. Evaluation of the proposed approach on a dataset containing many APT scenarios shows 84.21% of sensitivity and 82.16% of specificity.
引用
收藏
页数:40
相关论文
共 29 条
  • [1] Big knowledge-based semantic correlation for detecting slow and low-level advanced persistent threats
    Amir Mohammadzade Lajevardi
    Morteza Amini
    [J]. Journal of Big Data, 8
  • [2] A semantic-based correlation approach for detecting hybrid and low-level APTs
    Lajevardi, Amir Mohammadzade
    Amini, Morteza
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 96 : 64 - 88
  • [3] Expert knowledge and data analysis for detecting advanced persistent threats
    Ramon Moya, Juan
    DeCastro-Garcia, Noemi
    Fernandez-Diaz, Ramon-Angel
    Lorenzana Tamargo, Jorge
    [J]. OPEN MATHEMATICS, 2017, 15 : 1108 - 1122
  • [4] Automatic knowledge-based recognition of low-level tasks in ophthalmological procedures
    Lalys, Florent
    Bouget, David
    Riffaud, Laurent
    Jannin, Pierre
    [J]. INTERNATIONAL JOURNAL OF COMPUTER ASSISTED RADIOLOGY AND SURGERY, 2013, 8 (01) : 39 - 49
  • [5] Automatic knowledge-based recognition of low-level tasks in ophthalmological procedures
    Florent Lalys
    David Bouget
    Laurent Riffaud
    Pierre Jannin
    [J]. International Journal of Computer Assisted Radiology and Surgery, 2013, 8 : 39 - 49
  • [6] Detecting Network Threats using OSINT Knowledge-based IDS
    Vacas, Ivo
    Medeiros, Iberia
    Neves, Nuno
    [J]. 2018 14TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2018), 2018, : 128 - 135
  • [7] Detecting Advanced Persistent Threats Based on Entropy and Support Vector Machine
    Tan, Jiayu
    Wang, Jian
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2018, PT IV, 2018, 11337 : 153 - 165
  • [8] A Network Gene-Based Framework for Detecting Advanced Persistent Threats
    Wang, Yuan
    Wang, Yongjun
    Liu, Jing
    Huang, Zhijian
    [J]. 2014 NINTH INTERNATIONAL CONFERENCE ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING (3PGCIC), 2014, : 97 - 102
  • [9] Detecting Advanced Persistent Threats using Fractal Dimension based Machine Learning Classification
    Siddiqui, Sana
    Khan, Muhammad Salman
    Ferens, Ken
    Kinsner, Witold
    [J]. IWSPA'16: PROCEEDINGS OF THE 2016 ACM INTERNATIONAL WORKSHOP ON SECURITY AND PRIVACY ANALYTICS, 2016, : 64 - 69
  • [10] Prior Knowledge based Advanced Persistent Threats Detection for IoT in a Realistic Benchmark
    Shen, Yu
    Simsek, Murat
    Kantarci, Burak
    Mouftah, Hussein T.
    Bagheri, Mehran
    Djukic, Petar
    [J]. 2022 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM 2022), 2022, : 3551 - 3556