arrow
Return

Fast attack detection system using log analysis and attack tree generation

delete2018-02-22
delete5
PRE
AI
D
Duhoe Kim
Y
Yong‐Hyun Kim
S
Shin, Dongil *
D
Dongkyoo Shin *
DOI:10.1007/s10586-018-2269-xdelete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Many government branches report that internal networks are managed safely by separating them from the outside, but there is often a vulnerability that allows malicious codes to attack an internal network. Recently, the Ministry of National Defense of Korea announced that the internal network operated by the Korean military was attacked though hacking. It is difficult to detect cyber-attacks in real time within an internal network, which can be connected to an Internet of Everything (IoE). In this paper, we propose a fast attack detection system for the internal network that can be used by the government or public organizations. This system generates a tree to which the attack level is applied, notifies the user when the level is reached, and can block the system before an attack. Using this system, it is possible to protect the data and physical aspects by preventing the destruction of a system with large amounts of data, including important confidential or intellectual property. The proposed method offers a proper methodology for designing a malware protection system by categorizing the problem into a tree structure.
Keywords:
Attack tree
Log analysis
Cyber attack
Attack detection
Attack data
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
Papers:
5.0K
Citations:
7.5K

Organization

S
Sejong University
Scholars:
8.3K
Papers: 1.1W
Citations: 1.5W
A
agency of defense development (add), republic of korea
Scholars:
1.3K
Papers: 1.4K
Citations: 3