Skip to search boxSkip to navigationSkip to main content

Enabling Visual Analytics via Alert-driven Attack Graphs

*Corresponding author for this work
  • Delft University of Technology
    ,
  • Rochester Institute of Technology
Research Output:
Chapter in Book/Report/Conference proceeding
Conference contribution

Open access

Abstract

Attack graphs (AG) are a popular area of research that display all the paths an attacker can exploit to penetrate a network. Existing techniques for AG generation rely heavily on expert input regarding vulnerabilities and network topology. In this work, we advocate the use of AGs that are built directly using the actions observed through intrusion alerts, without prior expert input. We have developed an unsupervised visual analytics system, called SAGE, to learn alert-driven attack graphs. We show how these AGs (i) enable forensic analysis of prior attacks, and (ii) enable proactive defense by providing relevant threat intelligence regarding attacker strategies. We believe that alert-driven AGs can play a key role in AI-enabled cyber threat intelligence as they open up new avenues for attacker strategy analysis whilst reducing analyst workload.

Bibliographic Information

Output type

Research Output:
Chapter in Book/Report/Conference proceeding
Conference contribution

Original language

English

Pages from-to (Number of pages)

Pages 2420-2422 (3 pages)

Publication milestones

  • Published - 13/11/2021

Publication status

Published - 13/11/2021

Publisher

Association for Computing Machinery, Inc

Publication series

  • Publication series name: Proceedings of the ACM Conference on Computer and Communications Security
    ISSN (Print): 1543-7221

ISBN (Electronic)

9781450384544

Publication IDs

  • Scopus: 85119383217

Host publication title

CCS 2021 - Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security