Locating victims of destructive targeted attacks based on Suspicious Activity Spike Train
Nobutaka Kawaguchi, Hideyuki Tomimura, Tetsutoshi Komiyama, Kosuke Kubota, Mamoru Tsuichihara · 2017
In recent years, many organizations, companies and government agencies have been suffering from brutality of targeted attacks. Especially, destructive targeted attacks such as Shamoon and Samas have been causing significant damages on the targets' cyber assets, disputing their critical business operations. Since such attacks tend to access many hosts simultaneously, a rapid incident response is essential to prevent serious damages. To realize a rapid response, the responders need to locate all the victim hosts immediately after the first victim host raises a detection alarm. In this paper, we propose a novel method, called Suspicious Activity Spike Train (SAST) that locates potential attack victims by computing similarity between activity patterns of the detected first victim and the other hosts. SAST is based on the observation that the destructive targeted attack causes multiple hosts to perform similar types of suspicious activities synchronically. SAST employs spike trains that records when and which types of activities have been recently observed at each host, and then computes the trains' similarity at an abstract level. Thus, SAST is more robust than traditional indicators such as file hash values. Through the evaluation experiments with a real-world attack example, we demonstrate that immediately after the first victim is detected, SAST can locate all the victims in a testbed with a false positive rate of 0.4% before many victims' assets are tampered. Also, we show SAST is more effective than naïve approaches which do not fully utilize features of the attack.