An experiment using factor graph for early attack detection
Phuong Cao · Illinois Digital Environment for Access to Learning and Scholarship (University of Illinois at Urbana-Champaign) · 2015
This paper presents a factor graph based framework (named AttackTagger) for high accuracy and preemptive detection of attacks. We use security logs of real-incidents that occurred over a six-year period at the National Center for Supercomputing Applications (NCSA) at the University of Illinois to evaluate AttackTagger. Our data consist of attacks that led directly to the target system being compromised, i.e., not detected in advance, either by the security analysts or by intrusion detection systems. AttackTagger can detect 74 percent of attacks before the system misuse. AttackTagger uncovered six hidden attacks that were not detected by security analysts.