APIN: Automatic Attack Path Identification in Computer Networks

2020 IEEE International Conference on Intelligence and Security Informatics (ISI)(2020)

引用 1|浏览11
暂无评分
摘要
Identifying the scope of a network attack can be difficult with limited information about the nature of the attack. Even more difficult is the automation of this process. Because of this, it is important to investigate new methods for mapping and quantifying the threat posed by an attack, in order to prioritize actions during incident response. To this end we propose a framework for automatic attack path identification in computer networks (APIN) by leveraging observable malicious behaviors to quantify the threat score of a set of attacks. Using two academic datasets, experimental results show that APIN is able to quickly reconstruct paths that offer meaningful insight into the nature of multi-step threats on the network, given only reasonable restrictions on network size and structure. These insights would not be possible with only existing tools, such as IDSs, and human analysts would require significant time and expertise to obtain the same findings without APIN's guidance.
更多
查看译文
关键词
Attack Path,Threat Score,Alert Prioritization,Intrusion Detection,Cyber Attack,Incident Response
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要