Situational awareness of a coordinated cyber attack

被引:6
|
作者
Sudit, M [1 ]
Stotz, A [1 ]
Holender, M [1 ]
机构
[1] SUNY Buffalo, Ctr Multisource Informat Fus, Buffalo, NY 14260 USA
关键词
INFERD; ECCARS; fusion; information fusion; situational assessment; situational awareness; cyber attack; cyber warfare; attack detection; intrusion detection;
D O I
10.1117/12.606980
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
As technology continues to advance, services and capabilities become computerized, and an ever increasing amount of business is conducted electronically the threat of cyber attacks gets compounded by the complexity of such attacks and the criticality of the information which must be secured. A new age of virtual warfare has dawned in which seconds can differentiate between the protection of vital information and/or services and a malicious attacker attaining their goal. In this paper we present a novel approach in the real-time detection of multistage coordinated cyber attacks and the promising initial testing results we have obtained. We introduce INFERD (INformation Fusion Engine for Real-time Decision-making), an adaptable information fusion engine which performs fusion at levels zero, one, and two to provide real-time situational assessment and its application to the cyber domain in the ECCARS (Event Correlation for Cyber Attack Recognition System) system. The advantages to our approach are fourfold: (1) The complexity of the attacks which we consider, (2) the level of abstraction in which the analyst interacts with the attack scenarios, (3) the speed at which the information fusion is presented and performed, and (4) our disregard for ad-hoc rules or a priori parameters.
引用
收藏
页码:114 / 129
页数:16
相关论文
共 50 条
  • [1] Designing a Cyber Attack Information System for National Situational Awareness
    Skopik, Florian
    Ma, Zhendong
    Smith, Paul
    Bleier, Thomas
    [J]. FUTURE SECURITY, 2012, 318 : 277 - 288
  • [2] Integrated Situational Awareness for Cyber Attack Detection, Analysis, and Mitigation
    Cheng, Yi
    Sagduyu, Yalin
    Deng, Julia
    Li, Jason
    Liu, Peng
    [J]. SENSORS AND SYSTEMS FOR SPACE APPLICATIONS V, 2012, 8385
  • [3] Cyber situational awareness
    Leopold, H.
    [J]. ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2015, 132 (02): : 97 - 100
  • [4] Cyber Situational Awareness
    Helmut Leopold
    [J]. e & i Elektrotechnik und Informationstechnik, 2015, 132 (2) : 97 - 100
  • [5] Attack Graph Embedded Machine Learning Platform For Cyber Situational Awareness
    Haque, Ariful
    Shetty, Sachin
    Kamhoua, Charles A.
    Gold, Kimberly
    [J]. 2022 IEEE MILITARY COMMUNICATIONS CONFERENCE (MILCOM), 2022,
  • [6] Cyber Security Situational Awareness
    Tianfield, Huaglory
    [J]. 2016 IEEE INTERNATIONAL CONFERENCE ON INTERNET OF THINGS (ITHINGS) AND IEEE GREEN COMPUTING AND COMMUNICATIONS (GREENCOM) AND IEEE CYBER, PHYSICAL AND SOCIAL COMPUTING (CPSCOM) AND IEEE SMART DATA (SMARTDATA), 2016, : 782 - 787
  • [7] Predicting Cyber-Attack using Cyber Situational Awareness: The Case of Independent Power Producers (IPPs)
    Matey, Akwetey Henry
    Danquah, Paul
    Koi-Akrofi, Godfred Yaw
    [J]. INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (01) : 700 - 709
  • [8] Situational Awareness of E-learning System Based on Cyber-Attack and Vulnerability
    Zhu, Linkai
    Wang, Wennan
    Luo, Ruijie
    Cai, Zhiming
    Peng, Sheng
    Zhang, Zeyu
    [J]. ADVANCES IN WEB-BASED LEARNING - ICWL 2021, 2021, 13103 : 154 - 159
  • [9] Cyber situational awareness and differential hardening
    Dwivedi, Anurag
    Tebben, Dan
    [J]. CYBER SENSING 2012, 2012, 8408
  • [10] A Computational Model of Cyber Situational Awareness
    Dobson, Geoffrey B.
    Carley, Kathleen M.
    [J]. SOCIAL, CULTURAL, AND BEHAVIORAL MODELING, SBP-BRIMS 2018, 2018, 10899 : 395 - 400