Attack chain detection.

Saved in:
Bibliographic Details
Title: Attack chain detection.
Authors: Sexton, Joseph1, Storlie, Curtis1, Neil, Joshua1
Source: Statistical Analysis & Data Mining. Oct2015, Vol. 8 Issue 5/6, p353-363. 11p.
Subjects: Detectors, Computer security research, Communication methodology, Probability theory, Power electronics
Abstract: A targeted network intrusion typically evolves through multiple phases, termed the attack chain. When appropriate data are monitored, these phases will generate multiple events across the attack chain on a compromised host. It is shown empirically that events in different parts of the attack chain are largely independent under nonattack conditions. This suggests that a powerful detector can be constructed by combining across events spanning the attack. This article describes the development of such a detector for a larger network. To construct events that span the attack chain, multiple data sources are used, and the detector combines across events observed on the same machine, across local neighborhoods of machines linked by network communications, as well as across events observed on multiple computers. A probabilistic approach for evaluating the combined events is developed, and empirical investigations support the underlying assumptions. The detection power of the approach is studied by inserting plausible attack scenarios into observed network and host data, and an application to a real-world intrusion is given. [ABSTRACT FROM AUTHOR]
Copyright of Statistical Analysis & Data Mining is the property of Wiley-Blackwell and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Full text is not displayed to guests.
FullText Links:
  – Type: pdflink
Text:
  Availability: 1
Header DbId: egs
DbLabel: Engineering Source
An: 110464252
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Attack chain detection.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Sexton%2C+Joseph%22">Sexton, Joseph</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Storlie%2C+Curtis%22">Storlie, Curtis</searchLink><relatesTo>1</relatesTo><br /><searchLink fieldCode="AR" term="%22Neil%2C+Joshua%22">Neil, Joshua</searchLink><relatesTo>1</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Statistical+Analysis+%26+Data+Mining%22">Statistical Analysis & Data Mining</searchLink>. Oct2015, Vol. 8 Issue 5/6, p353-363. 11p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Detectors%22">Detectors</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+security+research%22">Computer security research</searchLink><br /><searchLink fieldCode="DE" term="%22Communication+methodology%22">Communication methodology</searchLink><br /><searchLink fieldCode="DE" term="%22Probability+theory%22">Probability theory</searchLink><br /><searchLink fieldCode="DE" term="%22Power+electronics%22">Power electronics</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: A targeted network intrusion typically evolves through multiple phases, termed the attack chain. When appropriate data are monitored, these phases will generate multiple events across the attack chain on a compromised host. It is shown empirically that events in different parts of the attack chain are largely independent under nonattack conditions. This suggests that a powerful detector can be constructed by combining across events spanning the attack. This article describes the development of such a detector for a larger network. To construct events that span the attack chain, multiple data sources are used, and the detector combines across events observed on the same machine, across local neighborhoods of machines linked by network communications, as well as across events observed on multiple computers. A probabilistic approach for evaluating the combined events is developed, and empirical investigations support the underlying assumptions. The detection power of the approach is studied by inserting plausible attack scenarios into observed network and host data, and an application to a real-world intrusion is given. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Statistical Analysis & Data Mining is the property of Wiley-Blackwell and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=110464252
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1002/sam.11296
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 11
        StartPage: 353
    Subjects:
      – SubjectFull: Detectors
        Type: general
      – SubjectFull: Computer security research
        Type: general
      – SubjectFull: Communication methodology
        Type: general
      – SubjectFull: Probability theory
        Type: general
      – SubjectFull: Power electronics
        Type: general
    Titles:
      – TitleFull: Attack chain detection.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Sexton, Joseph
      – PersonEntity:
          Name:
            NameFull: Storlie, Curtis
      – PersonEntity:
          Name:
            NameFull: Neil, Joshua
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 10
              Text: Oct2015
              Type: published
              Y: 2015
          Identifiers:
            – Type: issn-print
              Value: 19321864
          Numbering:
            – Type: volume
              Value: 8
            – Type: issue
              Value: 5/6
          Titles:
            – TitleFull: Statistical Analysis & Data Mining
              Type: main
ResultId 1