Detection and Threat Prioritization of Pivoting Attacks in Large Networks

被引:15
作者
Apruzzese, Giovanni [1 ]
Pierazzi, Fabio [1 ]
Colajanni, Michele [1 ]
Marchetti, Mirco [1 ]
机构
[1] Univ Modena & Reggio Emilia, Dept Engn Enzo Ferrari, I-41121 Modena, Italy
关键词
Protocols; Detection algorithms; Security; Proposals; Organizations; Algorithm design and analysis; Malware; Pivoting; graph; island-hopping; lateral movement; WORM DETECTION;
D O I
10.1109/TETC.2017.2764885
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Several advanced cyber attacks adopt the technique of "pivoting" through which attackers create a command propagation tunnel through two or more hosts in order to reach their final target. Identifying such malicious activities is one of the most tough research problems because of several challenges: command propagation is a rare event that cannot be detected through signatures, the huge amount of internal communications facilitates attackers evasion, timely pivoting discovery is computationally demanding. This paper describes the first pivoting detection algorithm that is based on network flows analyses, does not rely on any a-priori assumption on protocols and hosts, and leverages an original problem formalization in terms of temporal graph analytics. We also introduce a prioritization algorithm that ranks the detected paths on the basis of a threat score thus letting security analysts investigate just the most suspicious pivoting tunnels. Feasibility and effectiveness of our proposal are assessed through a broad set of experiments that demonstrate its higher accuracy and performance against related algorithms.
引用
收藏
页码:404 / 415
页数:12
相关论文
共 34 条
  • [1] [Anonymous], 2010, WORKING NOTES 2010 A
  • [2] [Anonymous], 2008, BOTMINER CLUSTERING
  • [3] [Anonymous], 2014, CISCO ANN SECURITY R
  • [4] Arora A., 2013, P 12 INT C COGN MOD, P336
  • [5] Ayala L., 2016, Cybersecurity for Hospitals and Healthcare Facilities: A Guide to Detection and Prevention
  • [6] Bilge L., 2011, P NDSS SAN DIEG CA
  • [7] Bilge L, 2012, 28TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2012), P129
  • [8] Brewer Ross, 2014, Network Security, V2014, P5, DOI 10.1016/S1353-4858(14)70040-6
  • [9] Playing Hide-and-Seek: An Abstract Game for Cyber Security
    Chapman, Martin
    Tyson, Gareth
    McBurney, Peter
    Luck, Michael
    Parsons, Simon
    [J]. 1ST INTERNATIONAL WORKSHOP ON AGENTS & CYBERSECURITY, 2014,
  • [10] Collins MP, 2007, LECT NOTES COMPUT SC, V4637, P276