Analysis of high volumes of network traffic for Advanced Persistent Threat detection

被引:111
|
作者
Marchetti, Mirco [1 ]
Pierazzi, Fabio [1 ]
Colajanni, Michele [1 ]
Guido, Alessandro [1 ]
机构
[1] Univ Modena & Reggio Emilia, Dept Engn Enzo Ferrari, Modena, MO, Italy
关键词
Security analytics; Traffic analysis; Advanced Persistent Threats; Data exfiltration; ANOMALY DETECTION;
D O I
10.1016/j.comnet.2016.05.018
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Advanced Persistent Threats (APTs) are the most critical menaces to modern organizations and the most challenging attacks to detect. They span over long periods of time, use encrypted connections and mimic normal behaviors in order to evade detection based on traditional defensive solutions. We propose an innovative approach that is able to analyze efficiently high volumes of network traffic to reveal weak signals related to data exfiltrations and other suspect APT activities. The final result is a ranking of the most suspicious internal hosts; this rank allows security specialists to focus their analyses on a small set of hosts out of the thousands of machines that typically characterize large organizations. Experimental evaluations in a network environment consisting of about 10K hosts show the feasibility and effectiveness of the proposed approach. Our proposal based on security analytics paves the way to novel forms of automatic defense aimed at early detection of APTs in large and continuously varying networked systems. (C) 2016 Elsevier B.V. All rights reserved.
引用
收藏
页码:127 / 141
页数:15
相关论文
共 50 条
  • [21] Advanced Persistent Threat Attack Detection using Clustering Algorithms
    Alsanad, Ahmed
    Altuwaijri, Sara
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2022, 13 (09) : 640 - 649
  • [22] The prevent of advanced persistent threat
    Beijing University of Posts and Telecommunications, China
    不详
    不详
    J. Chem. Pharm. Res., 7 (572-576):
  • [23] A Study on Advanced Persistent Threat
    Cinar, Cihan
    Alkan, Mustafa
    Dorterler, Murat
    Dogru, Ibrahim Alper
    2018 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND ENGINEERING (UBMK), 2018, : 116 - 121
  • [24] Modeling Attack Process of Advanced Persistent Threat Using Network Evolution
    Niu, Weina
    Zhang, Xiaosong
    Yang, Guowu
    Chen, Ruidong
    Wang, Dong
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2017, E100D (10): : 2275 - 2286
  • [25] A New Realistic Benchmark for Advanced Persistent Threats in Network Traffic
    Liu, Jinxin
    Shen, Yu
    Simsek, Murat
    Kantarci, Burak
    Mouftah, Hussein T.
    Bagheri, Mehran
    Djukic, Petar
    IEEE Networking Letters, 2022, 4 (03): : 162 - 166
  • [26] Deep Reinforcement Learning for Advanced Persistent Threat Detection in Wireless Networks
    Saheed, Kazeem
    Henna, Shagufta
    2023 31ST IRISH CONFERENCE ON ARTIFICIAL INTELLIGENCE AND COGNITIVE SCIENCE, AICS, 2023,
  • [27] Temporal Behavior in Network Traffic as a Basis for Insider Threat Detection
    Rajchel, Brett
    Monaco, John, V
    Singh, Gurminder
    Hu, Angela
    Shingleton, Jarrod
    Anderson, Thomas
    2020 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (SSCI), 2020, : 1427 - 1434
  • [28] Advanced Persistent Threat Detection and Mitigation Using Machine Learning Model
    Sakthivelu, U.
    Kumar, C. N. S. Vinoth
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2023, 36 (03): : 3691 - 3707
  • [29] Advanced Persistent Threat Detection Using Data Provenance and Metric Learning
    Akbar, Khandakar Ashrafi
    Wang, Yigong
    Ayoade, Gbadebo
    Gao, Yang
    Singhal, Anoop
    Khan, Latifur
    Thuraisingham, Bhavani
    Jee, Kangkook
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (05) : 3957 - 3969
  • [30] Detection of Command and Control in Advanced Persistent Threat based on Independent Access
    Wang, Xu
    Zheng, Kangfeng
    Niu, Xinxin
    Wu, Bin
    Wu, Chunhua
    2016 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2016,