Triage of IoT Attacks Through Process Mining

被引:8
|
作者
Coltellese, Simone [1 ]
Maggi, Fabrizio Maria [2 ]
Marrella, Andrea [1 ]
Massarelli, Luca [1 ]
Querzoni, Leonardo [1 ]
机构
[1] Sapienza Univ Roma, DIAG, Rome, Italy
[2] Univ Tartu, Tartu, Estonia
基金
欧盟地平线“2020”;
关键词
IoT security; Process mining; Behavioral attack analysis; PROCESS EXECUTIONS; PROCESS MODELS;
D O I
10.1007/978-3-030-33246-4_22
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The impressive growth of the IoT we witnessed in the recent years came together with a surge in cyber attacks that target it. Factories adhering to digital transformation programs are quickly adopting the IoT paradigm and are thus increasingly exposed to a large number of cyber threats that need to be detected, analyzed and appropriately mitigated. In this scenario, a common approach that is used in large organizations is to setup an attack triage system. In this setting, security operators can cherry-pick new attack patterns requiring further in-depth investigation from a mass of known attacks that can be managed automatically. In this paper, we propose an attack triage system that helps operators to quickly identify attacks with unknown behaviors, and later analyze them in detail. The novelty introduced by our solution is in the usage of process mining techniques to model known attacks and identify new variants. We demonstrate the feasibility of our approach through an evaluation based on three well-known IoT botnets, BASHLITE, LIGHTAIDRA and MIRAI, and on real current attack patterns collected through an IoT honeypot.
引用
下载
收藏
页码:326 / 344
页数:19
相关论文
共 50 条
  • [1] A Bridging Model for Process Mining and IoT
    Bertrand, Yannis
    De Weerdt, Jochen
    Serral, Estefania
    PROCESS MINING WORKSHOPS, ICPM 2021, 2022, 433 : 98 - 110
  • [2] A Process Mining Tool for Supporting IoT Security
    Hemmer, Adrien
    Badonnel, Remi
    Francois, Jerome
    Chrisment, Isabelle
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [3] A Process Mining Approach for Supporting IoT Predictive Security
    Hemmer, Adrien
    Badonnel, Remi
    Chrisment, Isabelle
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [4] Visualization of Process Model through Process Mining
    Kumar, Manoj M., V
    Kumar, Rahul
    Tejaswi, S. G. K.
    2019 10TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2019,
  • [5] An Expert-Validated Bridging Model for IoT Process Mining
    Bertrand, Yannis
    De Weerdt, Jochen
    Serral, Estefania
    BUSINESS & INFORMATION SYSTEMS ENGINEERING, 2024, 66 (6) : 737 - 756
  • [6] Comparative Assessment of Process Mining for Supporting IoT Predictive Security
    Hemmer, Adrien
    Abderrahim, Mohamed
    Badonnel, Remi
    Francois, Jerome
    Chrisment, Isabelle
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2021, 18 (01): : 1092 - 1103
  • [7] Defining Data Quality Issues in Process Mining with IoT Data
    Bertrand, Yannis
    Van Belle, Rafael
    De Weerdt, Jochen
    Serral, Estefania
    PROCESS MINING WORKSHOPS, ICPM 2022, 2023, 468 : 422 - 434
  • [8] Detecting IoT Botnet Attacks through Ensemble and Meta Ensemble Approaches
    Ma, Xiangjun
    He, Jingsha
    Nazir, Ahsan
    Zhu, Nafei
    Hu, Xiao
    Ullah, Faheem
    Wajahat, Ahsan
    Luo, Yehong
    Qureshi, Sirajuddin
    International Journal of Network Security, 2024, 26 (05): : 885 - 900
  • [9] Security Attacks on IoT
    Okul, S.
    Aydin, M. Ali
    2017 INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2017, : 1 - 5
  • [10] Middleware Adaptation through Process Mining
    Rosa, Nelson
    2017 IEEE 31ST INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (AINA), 2017, : 244 - 251