arrow
Return

Alert-Driven Attack Graph Generation Using S-PDFA

delete2021-01-01
delete31
delete
OA
AI
A
Azqa Nadeem *
S
Sicco Verwer
S
Stephen Moskal
S
Shanchieh Jay Yang
DOI:10.1109/TDSC.2021.3117348delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Ideal cyber threat intelligence (CTI) includes insights into attacker strategies that are specific to a network under observation. Such CTI currently requires extensive expert input for obtaining, assessing, and correlating system vulnerabilities into a graphical representation, often referred to as an attack graph (AG). Instead of deriving AGs based on system vulnerabilities, this work advocates the direct use of intrusion alerts. We propose SAGE, an explainable sequence learning pipeline that automatically constructs AGs from intrusion alerts without a priori expert knowledge. SAGE exploits the temporal and probabilistic dependence between alerts in a suffix-based probabilistic deterministic finite automaton (S-PDFA) - a model that brings infrequent severe alerts into the spotlight and summarizes paths leading to them. Attack graphs are extracted from the model on a per-victim, per-objective basis. SAGE is thoroughly evaluated on three open-source intrusion alert datasets collected through security testing competitions in order to analyze distributed multi-stage attacks. SAGE compresses over 330k alerts into 93 AGs that show how specific attacks transpired. The AGs are succinct, interpretable, and provide directly relevant insights into strategic differences and fingerprintable paths. They even show that attackers tend to follow shorter paths after they have discovered a longer one in 84.5% of the cases.
Keywords:
Security
Pipelines
Probabilistic logic
Learning automata
Testing
Special issues and sections
Markov processes
Alert-driven attack graphs
explainable machine learning
suffix automaton model
attacker strategy
intrusion alerts

Journal

IEEE Transactions on Dependable and Secure Computing cover
IEEE Transactions on Dependable and Secure Computing
IF:
7.5
Papers:
2.5K
Citations:
9.6K

Organization

R
Rochester Institute of Technology
Scholars:
3.8K
Papers: 3.3K
Citations: 45
D
Delft University of Technology
Scholars:
2.6W
Papers: 2.5W
Citations: 3.8W
Cited Papers

Cited Papers

Viral kinetics can predict early response to alpha‐interferon in chronic hepatitis C
err2008-12-10
err0
PREAI
errK. M. Walsh; T. Good; S. Cameron; D. Thorburn; E. A. B. McCruden; P. R. Mills; A. J. Morris
errShare
errSave
Attack scenario reconstruction approach using attack graph and alert data mining
err2020-10-01
err25
PREAI
errHu, Hao; Liu, Jing; Zhang, Yuchen; Liu, Yuling; Xu, Xiaoyu; Tan, Jinglei
errShare
errSave
Positive Effects of Elevated Platforms and Straw Bales on the Welfare of Fast-Growing Broiler Chickens Reared at Two Different Stocking Densities
err2022-02-22
err0
errOAAI
errFrédérique Mocz; Virginie Michel; Mathilde Janvrot; Jean-Philippe Moysan; Alassane Keita; Anja B. Riber; Maryse Guinebretière
errShare
errSave
errShare
errSave
Coupling model of standard single-mode and capillary fiber
err2009-10-07
err0
PREAI
errXiaoliang Zhu; Libo Yuan; Jun Yang; Shouxiu Cao
errShare
errSave
Explainable Machine Learning for Scientific Insights and Discoveries
err2020-01-01
err588
errOAAI
errRoscher, Ribana; Bohn, Bastian; Duarte, Marco F.; Garcke, Jochen
errShare
errSave
researcher View more