DACA: Automated Attack Scenarios and Dataset Generation

被引:0
|
作者
Korving, Frank [1 ]
Vaarandi, Risto [1 ]
机构
[1] Tallinn Univ Technol, Ctr Digital Forens & Cyber Secur, Tallinn, Estonia
关键词
security dataset; testbed; DevOps; detection engineering;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Computer networks and systems are under an ever-increasing risk of being attacked and abused. High-quality datasets can assist with in-depth analysis of attack scenarios, improve detection rules, and help educate analysts. However, existing solutions for creating such datasets suffer from a number of drawbacks. First, several solutions are not open source with publicly released implementations or are not vendor neutral. Second, some existing solutions neglect the complexity and variance of specific attack techniques when creating datasets or neglect certain attack types. Third, existing solutions are not fully automating the entire data collection pipeline. This paper presents and discusses the Dataset Creation and Acquisition Engine (DACA), a configurable dataset generation testbed, built around commonly used Infrastructure-as-Code (IaC) and DevOps tooling which can be used to create varied, reproducible datasets in a highly automated fashion. DACA acts as a versatile wrapper around existing virtualization technologies and can be used by blue as well as red teamers alike to run attack scenarios and generate datasets. These in turn can be used for tuning detection rules, for educational purposes or pushed into data processing pipelines for further analysis. To show DACA's effectiveness, DACA is used to create two extensive datasets examining covert DNS Tunnelling activity on which a detailed analysis is performed.
引用
收藏
页码:550 / 558
页数:9
相关论文
共 50 条
  • [31] Automated Dataset Generation for Training Peer-to-Peer Machine Learning Classifiers
    Roozbeh Zarei
    Alireza Monemi
    Muhammad Nadzir Marsono
    Journal of Network and Systems Management, 2015, 23 : 89 - 110
  • [32] Automated Generation of Synthetic in-Car Dataset for Human Body Pose Detection
    Borges, Joao
    Oliveira, Bruno
    Torres, Helena
    Rodrigues, Nelson
    Queiros, Sandro
    Shiller, Maximilian
    Coelho, Victor
    Pallauf, Johannes
    Brito, Jose Henrique
    Mendes, Jose
    Fonseca, Jaime C.
    PROCEEDINGS OF THE 15TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER VISION, IMAGING AND COMPUTER GRAPHICS THEORY AND APPLICATIONS, VOL 5: VISAPP, 2020, : 550 - 557
  • [33] Automated Dataset Generation for Training Peer-to-Peer Machine Learning Classifiers
    Zarei, Roozbeh
    Monemi, Alireza
    Marsono, Muhammad Nadzir
    JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2015, 23 (01) : 89 - 110
  • [34] Automatic dataset generation for automated program repair of bugs and vulnerabilities through SonarQube
    del-Hoyo-Gabaldon, Jesus -Angel
    Moreno-Cediel, Antonio
    Garcia-Lopez, Eva
    Garcia-Cabot, Antonio
    de-Fitero-Dominguez, David
    SOFTWAREX, 2024, 26
  • [35] Scrape, Cut, Paste and Learn: Automated Dataset Generation Applied to Parcel Logistics
    Naumann, Alexander
    Hertlein, Felix
    Zhou, Benchun
    Doerr, Laura
    Furmans, Kai
    2022 21ST IEEE INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND APPLICATIONS, ICMLA, 2022, : 1026 - 1031
  • [36] Scalable Analysis of Attack Scenarios
    Albanese, Massimiliano
    Jajodia, Sushi
    Pugliese, Andrea
    Subrahmanian, V. S.
    COMPUTER SECURITY - ESORICS 2011, 2011, 6879 : 416 - +
  • [37] Automated Generation of Virtual Road Scenarios for Efficient Tests of Driver Assistance Systems
    Thieling, Joern
    Mathar, Manuel
    Rossmann, Juergen
    2017 IEEE AUTOTESTCON, 2017, : 311 - 319
  • [38] A Method for Semi-automated Generation of Test Scenarios based on Use Cases
    Lipka, Richard
    Potuzak, Tomas
    Brada, Premek
    Hnetynka, Petr
    Vinarek, Jiri
    PROCEEDINGS 41ST EUROMICRO CONFERENCE ON SOFTWARE ENGINEERING AND ADVANCED APPLICATIONS SEAA 2015, 2015, : 241 - 244
  • [39] Generalization Generation of Hazardous Lane-changing Scenarios for Automated Vehicle Testing
    Zhao X.-M.
    Zhao Y.-Y.
    Jing S.-C.
    Hui F.
    Liu J.-B.
    Zidonghua Xuebao/Acta Automatica Sinica, 2023, 49 (10): : 2211 - 2223
  • [40] An automated black box approach for web vulnerability identification and attack scenario generation
    Akrout, Rim
    Alata, Eric
    Kaaniche, Mohamed
    Nicomette, Vincent
    Journal of the Brazilian Computer Society, 2014, 20 (01) : 1 - 16