Event attribute tainting: A new approach for attack tracing and event correlation
Martin Ussath, Feng Cheng, Christoph Meinel · 2016
The number of revealed and analyzed attacks that use sophisticated and complex methods increased lately. Through the usage of such methods the attackers are able to evade existing security systems and prevent a comprehensive detection of the malicious activities. Therefore, it is often necessary to perform a manual investigation of complex attacks, to identify all steps and malicious activities that belong to an attack. One main objective of an investigation is to correlate existing events and reveal relations between different activities, to get a comprehensive overview of the attack. Due to the fact that the correlation is often done manually, this process is complex and time consuming. In this paper, we propose a new automated correlation approach that uses the tainting concept to identify related log events. The approach uses meaningful attributes as taint sources and a taint policy to propagate the taint to related events. For the identification of the correlations, it is also possible to use meta-information sources to support the correlation process. Furthermore, the tainting based approach allows to visualize the correlation results in a taint graph, which simplifies the traceability. We successfully evaluated the proposed approach with log events from a simulated attack where real world attack methods and tools were used. With the new approach it was possible to identify all events that recorded the malicious activities of the attacker and the created taint graph allowed a comprehensive retracing of the attack. Thus, the correlation approach can support investigations in an effective way, because it reduces the complexity of event correlation and the needed time.