Triage of IoT Attacks Through Process Mining

被引:8
|
作者
Coltellese, Simone [1 ]
Maggi, Fabrizio Maria [2 ]
Marrella, Andrea [1 ]
Massarelli, Luca [1 ]
Querzoni, Leonardo [1 ]
机构
[1] Sapienza Univ Roma, DIAG, Rome, Italy
[2] Univ Tartu, Tartu, Estonia
来源
ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2019 CONFERENCES | 2019年 / 11877卷
基金
欧盟地平线“2020”;
关键词
IoT security; Process mining; Behavioral attack analysis; PROCESS EXECUTIONS; PROCESS MODELS;
D O I
10.1007/978-3-030-33246-4_22
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The impressive growth of the IoT we witnessed in the recent years came together with a surge in cyber attacks that target it. Factories adhering to digital transformation programs are quickly adopting the IoT paradigm and are thus increasingly exposed to a large number of cyber threats that need to be detected, analyzed and appropriately mitigated. In this scenario, a common approach that is used in large organizations is to setup an attack triage system. In this setting, security operators can cherry-pick new attack patterns requiring further in-depth investigation from a mass of known attacks that can be managed automatically. In this paper, we propose an attack triage system that helps operators to quickly identify attacks with unknown behaviors, and later analyze them in detail. The novelty introduced by our solution is in the usage of process mining techniques to model known attacks and identify new variants. We demonstrate the feasibility of our approach through an evaluation based on three well-known IoT botnets, BASHLITE, LIGHTAIDRA and MIRAI, and on real current attack patterns collected through an IoT honeypot.
引用
收藏
页码:326 / 344
页数:19
相关论文
共 50 条
  • [31] Declarative process mining in healthcare
    Rovani, Marcella
    Maggi, Fabrizio M.
    de Leoni, Massimiliano
    van der Aalst, Wil M. P.
    EXPERT SYSTEMS WITH APPLICATIONS, 2015, 42 (23) : 9236 - 9251
  • [32] On Process Mining in Health Care
    Kaymak, Uzay
    Mans, Ronny
    van de Steeg, Tim
    Dierks, Meghan
    PROCEEDINGS 2012 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2012, : 1859 - 1864
  • [33] Process Mining: A Guide for Practitioners
    Milani, Fredrik
    Lashkeyich, Katsiaryna
    Maggi, Fabrizio Maria
    Di Francescomarino, Chiara
    RESEARCH CHALLENGES IN INFORMATION SCIENCE, 2022, 446 : 265 - 282
  • [34] Process mining and practical usage
    Tadanai, Ondrej
    Tanuska, Pavol
    INES 2015 - IEEE 19TH INTERNATIONAL CONFERENCE ON INTELLIGENT ENGINEERING SYSTEMS, 2015, : 63 - 67
  • [35] Analysis of Emergency Room Episodes Duration Through Process Mining
    Rojas, Eric
    Cifuentes, Andres
    Burattin, Andrea
    Munoz-Gama, Jorge
    Sepulveda, Marcos
    Capurro, Daniel
    BUSINESS PROCESS MANAGEMENT WORKSHOPS, BPM 2018 INTERNATIONAL WORKSHOPS, 2019, 342 : 251 - 263
  • [36] Teamwork Assessment in Collaborative Projects Through Process Mining Techniques
    Antonio Caballero-Hernandez, Juan
    Balderas, Antonio
    Palomo-Duarte, Manuel
    Delatorre, Pablo
    Reinoso, Antonio J.
    Manuel Dodero, Juan
    INTERNATIONAL JOURNAL OF ENGINEERING EDUCATION, 2020, 36 (01) : 470 - 482
  • [37] Supporting Governance in Healthcare Through Process Mining: A Case Study
    Agostinelli, Simone
    Covino, Federico
    D'Agnese, Giampaolo
    De Crea, Carmela
    Leotta, Francesco
    Marrella, Andrea
    IEEE ACCESS, 2020, 8 : 186012 - 186025
  • [38] Performance Analysis of Emergency Room Episodes Through Process Mining
    Rojas, Eric
    Cifuentes, Andres
    Burattin, Andrea
    Munoz-Gama, Jorge
    Sepulveda, Marcos
    Capurro, Daniel
    INTERNATIONAL JOURNAL OF ENVIRONMENTAL RESEARCH AND PUBLIC HEALTH, 2019, 16 (07)
  • [39] Internet of Things (IoT): Taxonomy of Security Attacks
    Nawir, Mukrimah
    Amir, Amiza
    Yaakob, Naimah
    Lynn, Ong Bi
    2016 3RD INTERNATIONAL CONFERENCE ON ELECTRONIC DESIGN (ICED), 2016, : 321 - 326
  • [40] A Survey on Security Attacks and Solutions in the IoT Network
    Liang, Xingwei
    Kim, Yoohwan
    2021 IEEE 11TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), 2021, : 853 - 859