Extracting and evaluating similar and unique cyber attack strategies from intrusion alerts
- Stephen Moskal,
- ,
- Michael E. Kuhl
- Rochester Institute of Technology
Abstract
Intrusion detection system (IDS) is an integral part of computer networks to monitor and detect threats. However, the alerts raised by these systems are often overwhelming to security analysts, making it difficult to uncover the steps an attacker took to compromise one or more systems in the network. This work presents a novel approach that aggregates IDS alerts and forms sequences of attack activities and their corresponding probabilistic models. This allows comparison of attack sequences to offer insights for unique as well as similar attack behaviors. We aggregate alerts by performing a Gaussian filter on specific alert attributes and model attackers using a suffix-based probabilistic model. We compare sequences generated from ten independent attacking teams with similar objectives demonstrating how our process uncovers similarities and uniqueness between the attacks that was not obvious. The sequences revealed by our process creates meaningful sequences that offers insights on how the attacking teams exploit a network.
Bibliographic Information
Output type
Original language
EnglishArticle number
8587402Pages from-to (Number of pages)
Pages 49-54 (6 pages)Publication milestones
- Published - 24/12/2018
Publication status
Publisher
Institute of Electrical and Electronics Engineers Inc.Publication series
- Publication series name: 2018 IEEE International Conference on Intelligence and Security Informatics, ISI 2018
ISBN (Electronic)
9781538678480Publication IDs
- Scopus: 85061061278
Host publication title
2018 IEEE International Conference on Intelligence and Security Informatics, ISI 2018Host publication editors
- Dongwon Lee
- Ghita Mezzour
- Ponnurangam Kumaraguru
- Nitesh Saxena
