Distributed log analysis for scenario-based detection of multi-step attacks and generation of near-optimal defense recommendations

Kerem Kaynar · 2017

Detecting related, ongoing actions of attackers is significant for providing a complete situational assessment of security and determining the most effective reactive defense measures for a network. The logs generated by software running across the network can be used for this purpose, since they may contain the traces of malicious activities occurring inside the network. Primary logs that indicate security alerts such as vulnerability exploits can be used to compute the attack paths that are likely being followed by the attackers. Attack graphs are utilized to represent the attack paths. One of the main contributions of this thesis work is the proposal of a distributed attack graph generation algorithm eliminating the scalability problem inherent in attack graph computation for even medium scale networks. Secondary logs are not directly related to security alerts. However, the usage of these logs can provide more insight into the activities of the attackers. We contribute to the secondary log processing by generating behavioural malware signatures and matching them to the secondary logs. The instantiated malware signatures are integrated with the computed attack graphs. The scalability problems caused by the high volume of secondary logs are alleviated by utilizing a stream-based Big Data infrastructure. Response to the ongoing attack scenarios is performed by applying an optimization method that utilizes a specifically designed candidate selection function and the computed attack graphs.

Read the paper · More papers on PaperTik