Book Chapter10.1007/978-3-030-71590-8_12
A Distributed Framework for APT Attack Analysis
Qi Yulu,Rong Jiang,Aiping Li,Zhaoquan Gu,Yan Jia +4 more
- 01 Jan 2021
- pp 199-219
TL;DR: Wang et al. as mentioned in this paper proposed a distributed framework for detecting the APT attacks on the Internet of Things (IoT) that interconnects physical devices, including intelligent transportation systems, telemedicine, smart grids, aerospace and many other fields.
read more
Abstract: Information security is an important part of Internet security. As more and more industries rely on the Internet, it has become urgent to protect information security of these industries, spawned local area networks (LANs), intranets and so on. With the development of information sensor technology, the Internet of Things (IoT) that interconnects physical devices has emerged. As a unity of computing process and physical process, the Cyber-physical systems (CPS) is the next generation intelligent system which integrates computing, communication and controlling capabilities. CPS covers a wide range of applications and critical infrastructures, including intelligent transportation systems, telemedicine, smart grids, aerospace, and many other fields. The APT attacks are typically conducted directly against these critical infrastructures around the world, which would incur severe consequences. It is meaningful to protect these information by detecting the APT attacks timely and accurately, and effective defensive measures could be adopted. Although the APT attacks seem destructive, the attack process are complex and changeable. In essence, the attack process usually follows certain rules. In this chapter, we introduce a distributed framework for detecting the APT attacks. Cyber security knowledge graph stores existing knowledge and the attack rules, which plays an important role in analyzing the attacks. We first analyze potential attack events by the proposed distributed framework on Spark, then we mine the attack chains from massive data with the spatial and temporal characteristics. These steps could help identify complicated attacks. We also conduct extensive experiments, the results show that the analysis accuracy depends on the completeness of the cyber security knowledge graph and the precision of the detection results from security equipments. With the rational expectation about more exposure of attacks and faster upgrade of security equipments, it is sufficient and necessary to improve the cyber security knowledge graph constantly for better performance.
read more
Chat with Paper
AI Agents for this Paper
Find similar papers on Google Scholar, PubMed and Arxiv
Write a critical review of this paper
Analyze citations of this paper to find unaddressed research gaps
References
Knowledge engineering: principles and methods
Rudi Studer,V. Richard Benjamins,V. Richard Benjamins,Dieter Fensel +3 more
- 01 Mar 1998
TL;DR: The paradigm shift from a transfer view to a modeling view is discussed and two approaches which considerably shaped research in Knowledge Engineering are described: Role-limiting Methods and Generic Tasks.
Rete: a fast algorithm for the many pattern/many object pattern match problem
TL;DR: The Rete Match Algorithm is an efficient method for comparing a large collection of patterns to a largeCollection of objects that finds all the objects that match each pattern.
2.7K
Constructing attack scenarios through correlation of intrusion alerts
Peng Ning,Yun Cui,Douglas S. Reeves +2 more
- 18 Nov 2002
TL;DR: A formal framework for alert correlation, the implementation of an off-line alert correlator based on the framework, and the evaluation of the method with the 2000 DARPA intrusion detection scenario specific datasets demonstrate the potential of the proposed method and its advantage over alternative methods.
A Practical Approach to Constructing a Knowledge Graph for Cybersecurity
TL;DR: A cybersecurity knowledge base and deduction rules based on a quintuple model is presented and the Stanford named entity recognizer (NER) is used to train an extractor to extract useful information.
225
A security risk analysis model for information systems: Causal relationships of risk factors and vulnerability propagation analysis
TL;DR: A security risk analysis model (SRAM) is proposed, which enables organizations to establish proactive security risk management plans for information systems, which is validated via a case study.
162