Multi-layer episode filtering for the multi-step attack detection

被引:27
|
作者
Soleimani, Mahbobeh [1 ]
Ghorbani, Ali A. [1 ]
机构
[1] Univ New Brunswick, Fac Comp Sci, Informat Secur Ctr Excellence, Fredericton, NB E3B 5A3, Canada
关键词
Alert correlation; Multi-step attack; Intrusion detection system;
D O I
10.1016/j.comcom.2012.04.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The discovery of sophisticated attack sequences demands the development of significantly better alert correlation algorithms. Most of the proposed approaches in the area of multi-step attack detection have limited capabilities because they rely on various forms of predefined knowledge of attacks or attack transition patterns using attack modeling language or pre-and post-conditions of individual attacks. Therefore, those approaches cannot recognize a correlation when an attack is new or the relationship between attacks is new. In this research, we take a different view and consider alert correlation as the problem of inferring an intruder's actions as alert patterns that are constructed progressively. The work is based on a multi-layer episode mining and filtering algorithm. A decision-tree-based method is used for learning specifications of each attack pattern and detecting them in alert streams. We also used a Correlation Weight Matrix (CWM) for encoding correlation strength between attack types in the attack scenarios. One of the distinguishing features of our proposed technique is detecting novel multi-step attack scenarios, using a rule prediction method. The results have shown that our approach can effectively discover known and unknown attack strategies with high accuracy. We achieved more than 90% reduction in the number of discovered patterns while more than 95% of final patterns were actual patterns. Furthermore, our rule prediction capability showed a precise forecasting ability in guessing future alerts. (C) 2012 Elsevier B.V. All rights reserved.
引用
收藏
页码:1368 / 1379
页数:12
相关论文
共 50 条
  • [1] A systematic survey on multi-step attack detection
    Navarro, Julio
    Deruyver, Aline
    Parrend, Pierre
    [J]. COMPUTERS & SECURITY, 2018, 76 : 214 - 249
  • [2] RTECA: Real time episode correlation algorithm for multi-step attack scenarios detection
    Ramaki, Ali Ahmadian
    Amini, Morteza
    Atani, Reza Ebrahimi
    [J]. COMPUTERS & SECURITY, 2015, 49 : 206 - 219
  • [3] Detection algorithm for multi-step attack based on CTPN
    Yan, Fen
    Huang, Hao
    Yin, Xin-Chun
    [J]. Jisuanji Xuebao/Chinese Journal of Computers, 2006, 29 (08): : 1383 - 1391
  • [4] MAD: A Middleware Framework for Multi-Step Attack Detection
    Papadopoulos, Panagiotis
    Petsas, Thanasis
    Christou, Giorgos
    Vasiliadis, Giorgos
    [J]. 2015 4TH INTERNATIONAL WORKSHOP ON BUILDING ANALYSIS DATASETS AND GATHERING EXPERIENCE RETURNS FOR SECURITY (BADGERS), 2015, : 8 - 15
  • [5] Multi-Step Attack Pattern Detection on Normalized Event Logs
    Jaeger, David
    Ussath, Martin
    Cheng, Feng
    Meinel, Christoph
    [J]. 2015 IEEE 2nd International Conference on Cyber Security and Cloud Computing (CSCloud), 2015, : 390 - 398
  • [6] Multi-Layer Filtering Approach for Hyperspectral Target Detection
    Zou, Zhengxia
    Shi, Zhenwei
    [J]. INTERNATIONAL SYMPOSIUM ON PHOTOELECTRONIC DETECTION AND IMAGING 2013: IMAGING SPECTROMETER TECHNOLOGIES AND APPLICATIONS, 2013, 8910
  • [7] Development of multi-step filtering processor
    Kim, M
    Lim, S
    Kim, J
    [J]. 6TH INTERNATIONAL CONFERENCE ON DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, PROCEEDINGS, 1999, : 169 - 176
  • [8] An Unsupervised Two-Layer Multi-Step Network Attack Detector
    Wang, Su
    Wang, Zhiliang
    Yin, Xia
    Shi, Xingang
    [J]. IEEE INFOCOM 2020 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2020, : 1308 - 1309
  • [9] MALICIOUS URL DETECTION USING MULTI-LAYER FILTERING MODEL
    Kumar, Rajesh
    Zhang, Xiaosong
    Tariq, Hussain Ahmad
    Khan, Riaz Ullah
    [J]. 2017 14TH INTERNATIONAL COMPUTER CONFERENCE ON WAVELET ACTIVE MEDIA TECHNOLOGY AND INFORMATION PROCESSING (ICCWAMTIP), 2017, : 97 - 100
  • [10] Multi-step vortex filtering for phase extraction
    Aguilar, Alberto
    Davila, Abundio
    Garcia-Marquez, Jorge
    [J]. OPTICS EXPRESS, 2014, 22 (07): : 8503 - 8514