Building suspiciousness cascading graph over multiple hosts for detecting targeted attacks
Nobutaka Kawaguchi, Hideyuki Tomimura, Mamoru Tsuichihara · 2016
In this paper, we propose a novel approach to detect a targeted attack by visualizing the paths of lateral movement in which the attacker compromises several hosts in the targeted network step by step to achieve his final goal. To this end, we first identify a pair of hosts that has a relationship in which a host can have compromised the other host based on the suspiciousness of their activities and communication patterns between them. Then we cluster such pairs as a graph visualizing an attack path. The attack is finally detected based on the graph size. Since this approach is agnostic to specific signatures, it can cope with a wide variety of attacks. The evaluation experiments show our approach achieves both the high detection rate of 97%, and the low false positives, which is 10% of an existing approach.