Multi-Step Attack Pattern Detection on Normalized Event Logs

被引:13
|
作者
Jaeger, David [1 ]
Ussath, Martin [1 ]
Cheng, Feng [1 ]
Meinel, Christoph [1 ]
机构
[1] Hasso Plattner Inst, Potsdam, Germany
关键词
pattern detection; attack signature; multi-step attack; event logs; normalization; threat intelligence; MODEL;
D O I
10.1109/CSCloud.2015.26
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Looking at recent cyber-attacks in the news, a growing complexity and sophistication of attack techniques can be observed. Many of these attacks are performed in multiple steps to reach the core of the targeted network. Existing signature detection solutions are focused on the detection of a single step of an attack, but they do not see the big picture. Furthermore, current signature languages cannot integrate valuable external threat intelligence, which would simplify the creation of complex signatures and enables the detection of malicious activities seen by other targets. We extend an existing multi-step signature language to support attack detection on normalized log events, which were collected from various applications and devices. Additionally, the extended language supports the integration of external threat intelligence and allows us to reference current threat indicators. With this approach, we can create generic signatures that stay up-to-date. Using our language, we could detect various login brute-force attempts on multiple applications with only one generic signature.
引用
收藏
页码:390 / 398
页数:9
相关论文
共 50 条
  • [41] MMSP: A LSTM Based Framework for Multi-Step Attack Prediction in Mixed Scenarios
    Cheng, Zijun
    Sun, Degang
    Wang, Leiqi
    Lv, Qiujian
    Wang, Yan
    2022 27TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2022), 2022,
  • [42] A Description Model of Multi-Step Attack Planning Domain Based on Knowledge Representation
    Hu Liang
    Xie Nannan
    Chai Sheng
    Nurbol
    CHINESE JOURNAL OF ELECTRONICS, 2013, 22 (03): : 437 - 441
  • [43] A Pattern Fusion Algorithm for Multi-Step Ahead Prediction of Surrogate Motion
    Zawisza, I.
    Yan, H.
    Yin, F.
    MEDICAL PHYSICS, 2014, 41 (06) : 98 - 99
  • [44] A multi-step predictor with a variable input pattern for system state forecasting
    Liu, Jie
    Wang, Wilson
    Golnaraghi, Farid
    MECHANICAL SYSTEMS AND SIGNAL PROCESSING, 2009, 23 (05) : 1586 - 1599
  • [45] PLANNING MULTI-STEP ERROR-DETECTION AND RECOVERY STRATEGIES
    DONALD, BR
    INTERNATIONAL JOURNAL OF ROBOTICS RESEARCH, 1990, 9 (01): : 3 - 60
  • [46] ENHANCING MULTI-STEP ACTION PREDICTION FOR ACTIVE OBJECT DETECTION
    Fang, Fen
    Xu, Qianli
    Gauthier, Nicolas
    Li, Liyuan
    Lim, Joo-Hwee
    2021 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2021, : 2189 - 2193
  • [47] Multi-step detection of cyanide ion by a bis(dimesitylboryl)dibenzoazaborine
    Agou, Tomohiro
    Sekine, Masaki
    Kobayashi, Junji
    Kawashima, Takayuki
    JOURNAL OF ORGANOMETALLIC CHEMISTRY, 2009, 694 (23) : 3833 - 3836
  • [48] Wideband Spectrum Sensing by Multi-step Sample Autocorrelation Detection
    Chen, Lu
    Wu, Xiaoqin
    Bai, Yong
    WIRELESS INTERNET (WICON 2016), 2018, 214 : 228 - 239
  • [49] Research on discovering multi-step attack patterns based on clustering IDS alert sequences
    Mei, Hai-Bin
    Gong, Jian
    Zhang, Ming-Hua
    Tongxin Xuebao/Journal on Communications, 2011, 32 (05): : 63 - 69
  • [50] A heuristic multi-step attack model generation method based on kill chain model
    Liu, Jianyi
    Lu, Chen
    Lin, Bingjie
    Guo, Han
    BASIC & CLINICAL PHARMACOLOGY & TOXICOLOGY, 2021, 128 : 36 - 37