首页> 外文会议> >An 'Attacker Centric' Cyber Attack Behavior Analysis Technique
【24h】

An 'Attacker Centric' Cyber Attack Behavior Analysis Technique

机译:一种“以攻击者为中心”的网络攻击行为分析技术

获取原文

摘要

Cyber attack behavior analysis can be roughly classified as "network centric" and "attacker centric" approaches. Compared with traditional "network centric" approach, the key to the implementation of "attacker centric" approach is to decide what to track, in other words, how to find the proper attacker set to be tracked. Current "attacker centric" approach researches mainly focus on single attacker centric behavior analysis, while overlooking the impact of the attacker''s cooperative relationship on attack behavior analysis. This paper is mainly coping with such scenarios. In this paper, the basic concept and methods of attack behavior tracking and analysis is introduced. As a key technique, the principles of choosing desirable attacker set are discussed, the concepts of attacker group and group member are introduced, and a simple algorithm of attacker group recognition is proposed. Finally, a prototype system based on the proposed approaches is evaluated under DARPA 2000 intrusion detection evaluation datasets. The experimental results show that our approach has potential in analyzing complex cooperative attacks.
机译:网络攻击行为分析可以粗略地分为“以网络为中心”和“以攻击者为中心”的方法。与传统的“以网络为中心”的方法相比,实施“以攻击者为中心”的方法的关键是确定要跟踪的内容,换句话说,如何找到要跟踪的适当攻击者集。当前的“以攻击者为中心”的方法研究主要集中在以单个攻击者为中心的行为分析上,而忽略了攻击者合作关系对攻击行为分析的影响。本文主要针对这种情况。介绍了攻击行为跟踪与分析的基本概念和方法。作为关键技术,讨论了选择理想的攻击者集合的原理,介绍了攻击者组和成员的概念,并提出了一种简单的攻击者组识别算法。最后,在DARPA 2000入侵检测评估数据集下评估了基于所提出方法的原型系统。实验结果表明,我们的方法在分析复杂的协作攻击方面具有潜力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号