首页> 外文期刊>Information, knowledge, systems management >Attack profiles to derive data observations, features, and characteristics of cyber attacks
【24h】

Attack profiles to derive data observations, features, and characteristics of cyber attacks

机译:攻击配置文件以获取数据观察,网络攻击的特征和特征

获取原文
获取原文并翻译 | 示例
           

摘要

Existing techniques for cyber attack detection rely mainly on activity data from computers and networks. Little consideration has been given to other kinds of data in the cause-effect chains of attacks. Adding state and performance data may reveal elements on computers and networks that are affected by a cyber attack, thus providing a more accurate, complete picture of an attack. This paper presents a System-Fault-Risk framework that defines elements involved in the cause-effect chain of an attack. The SFR framework combines system and fault modeling, and risk assessment methods. It is employed to analyze known cyber attacks and derive profiles that define activity, state and performance data in cause-effect chains, features of those data, and characteristics of those features that enable attack detection. The profiles derived from specific attacks are generalized and compared with those reported in other studies to illustrate a set of novel data, features and characteristics.
机译:现有的网络攻击检测技术主要依赖于计算机和网络的活动数据。在攻击的因果链中很少考虑其他类型的数据。添加状态和性能数据可能会揭示计算机和网络上受网络攻击影响的元素,从而提供更准确,完整的攻击情况。本文提出了一个System-Fault-Risk框架,该框架定义了攻击的因果链中涉及的元素。 SFR框架结合了系统和故障建模以及风险评估方法。它用于分析已知的网络攻击,并导出定义因果链中的活动,状态和性能数据,这些数据的特征以及能够进行攻击检测的那些特征的配置文件。对来自特定攻击的配置文件进行了概括,并与其他研究报告的配置文件进行了比较,以说明一组新颖的数据,特征和特征。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号