论文标题

用于映射入侵可观察物的网络攻击动作框架

Cyberattack Action-Intent-Framework for Mapping Intrusion Observables

论文作者

Moskal, Stephen, Yang, Shanchieh Jay

论文摘要

具有讽刺意味的是,网络对手使用的技术和策略变得越来越复杂,随着防御的强大和违规的成本持续上升。了解对手的思维过程和行为非常具有挑战性,因为高知名度甚至业余攻击者没有动力分享与其非法活动相关的交易。观察对手所执行的动作的一个机会是使用入侵检测系统(IDS),如果检测到可疑行为,该系统会产生警报。这些系统提出的警报通常通过攻击形式“签名”来描述可疑动作,这不一定会揭示攻击者执行动作的真正意图。同时,存在几个高级框架来描述对手可能执行的序列或作用类型的序列。但是,这些框架不会将动作类型连接到标准入侵检测系统的可观察物,也不会描述对抗性动作的合理意图。为了解决这些差距,这项工作提出了动作意愿框架(AIF),以补充现有的网络攻击杀死链条和攻击分类法。 AIF在两个描述层面上定义了一组动作意愿状态(AIS):宏观AIS描述了攻击者正在尝试实现的“什么”,而微AIS描述了“如何实现”目标。提供了两个宏的完整描述,以及一组指导原理,介绍了AIS如何得出和添加到框架中。

The techniques and tactics used by cyber adversaries are becoming more sophisticated, ironically, as defense getting stronger and the cost of a breach continuing to rise. Understanding the thought processes and behaviors of adversaries is extremely challenging as high profile or even amateur attackers have no incentive to share the trades associated with their illegal activities. One opportunity to observe the actions the adversaries perform is through the use of Intrusion Detection Systems (IDS) which generate alerts in the event that suspicious behavior was detected. The alerts raised by these systems typically describe the suspicious actions via the form of attack 'signature', which do not necessarily reveal the true intent of the attacker performing the action. Meanwhile, several high level frameworks exist to describe the sequence or chain of action types an adversary might perform. These frameworks, however, do not connect the action types to observables of standard intrusion detection systems, nor describing the plausible intents of the adversarial actions. To address these gaps, this work proposes the Action-Intent Framework (AIF) to complement existing Cyber Attack Kill Chains and Attack Taxonomies. The AIF defines a set of Action-Intent States (AIS) at two levels of description: the Macro-AIS describes 'what' the attacker is trying to achieve and the Micro-AIS describes "how" the intended goal is achieved. A full description of both the Macro is provided along with a set of guiding principals of how the AIS is derived and added to the framework.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源