DACA: Automated Attack Scenarios and Dataset Generation

被引:0
|
作者
Korving, Frank [1 ]
Vaarandi, Risto [1 ]
机构
[1] Tallinn Univ Technol, Ctr Digital Forens & Cyber Secur, Tallinn, Estonia
关键词
security dataset; testbed; DevOps; detection engineering;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Computer networks and systems are under an ever-increasing risk of being attacked and abused. High-quality datasets can assist with in-depth analysis of attack scenarios, improve detection rules, and help educate analysts. However, existing solutions for creating such datasets suffer from a number of drawbacks. First, several solutions are not open source with publicly released implementations or are not vendor neutral. Second, some existing solutions neglect the complexity and variance of specific attack techniques when creating datasets or neglect certain attack types. Third, existing solutions are not fully automating the entire data collection pipeline. This paper presents and discusses the Dataset Creation and Acquisition Engine (DACA), a configurable dataset generation testbed, built around commonly used Infrastructure-as-Code (IaC) and DevOps tooling which can be used to create varied, reproducible datasets in a highly automated fashion. DACA acts as a versatile wrapper around existing virtualization technologies and can be used by blue as well as red teamers alike to run attack scenarios and generate datasets. These in turn can be used for tuning detection rules, for educational purposes or pushed into data processing pipelines for further analysis. To show DACA's effectiveness, DACA is used to create two extensive datasets examining covert DNS Tunnelling activity on which a detailed analysis is performed.
引用
收藏
页码:550 / 558
页数:9
相关论文
共 50 条
  • [41] Attack sample generation algorithm based on data association group by GAN in industrial control dataset
    Zhou, Wen
    Kong, Xiang-min
    Li, Kai-li
    Li, Xiao-ming
    Ren, Lin-lin
    Yan, Yong
    Sha, Yun
    Cao, Xue-ying
    Liu, Xue-jun
    COMPUTER COMMUNICATIONS, 2021, 173 : 206 - 213
  • [42] Bin Picking System using Object Recognition based on Automated Synthetic Dataset Generation
    Jo, Hyun-Jun
    Min, Cheol-Hui
    Song, Jae-Bok
    2018 15TH INTERNATIONAL CONFERENCE ON UBIQUITOUS ROBOTS (UR), 2018, : 886 - 890
  • [43] Constructing Dataset of Functionally Equivalent Java Methods Using Automated Test Generation Techniques
    Higo, Yoshiki
    SSRN, 2023,
  • [44] Botnet dataset with simultaneous attack activity
    Putra, Muhammad Aidiel Rachman
    Hostiadi, Dandy Pramana
    Ahmad, Tohari
    DATA IN BRIEF, 2022, 45
  • [45] Botnet dataset with simultaneous attack activity
    Putra, Muhammad Aidiel Rachman
    Hostiadi, Dandy Pramana
    Ahmad, Tohari
    DATA IN BRIEF, 2022, 45
  • [46] HVAC system attack detection dataset
    Elnour, Mariam
    Meskin, Nader
    Khan, Khaled
    Jain, Raj
    DATA IN BRIEF, 2021, 37
  • [47] Automated generation of process simulation scenarios from declarative control-flow changes
    Barón-Espitia D.
    Dumas M.
    González-Rojas O.
    PeerJ Computer Science, 2024, 10
  • [48] Automated generation of process simulation scenarios from declarative control-flow changes
    Baron-Espitia, Daniel
    Dumas, Marlon
    Gonzalez-Rojas, Oscar
    PEERJ COMPUTER SCIENCE, 2024, 10
  • [49] Generation of Risky Scenarios for Testing Automated Driving Visual Perception Based on Causal Analysis
    Jiang, Zhengmin
    Liu, Jia
    Sun, Peng
    Sang, Ming
    Li, Huiyun
    Pan, Yi
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2024, 25 (11) : 15991 - 16004
  • [50] Generating attack scenarios with causal relationship
    Cheng, Yu-Chin
    Chen, Chien-Hung
    Chiang, Chung-Chih
    Wang, Jun-Wei
    Laih, Chi-Sung
    GRC: 2007 IEEE INTERNATIONAL CONFERENCE ON GRANULAR COMPUTING, PROCEEDINGS, 2007, : 368 - 373