Correlating cyber incident information to establish situational awareness in Critical Infrastructures
Title | Correlating cyber incident information to establish situational awareness in Critical Infrastructures |
Publication Type | Conference Paper |
Year of Publication | 2016 |
Authors | Settanni, G., Shovgenya, Y., Skopik, F., Graf, R., Wurzenberger, M., Fiedler, R. |
Conference Name | 2016 14th Annual Conference on Privacy, Security and Trust (PST) |
Date Published | dec |
Keywords | compositionality, computer network security, Correlation, critical infrastructure, critical infrastructure protection, critical infrastructures, cyber attack, cyber incident information correlation, cyber incidents handling, cyber situational awareness, Data Exfiltration, Europe, feature extraction, Human Behavior, human factors, information correlation, Joining processes, Mathematical model, Metrics, pubcrawl, Resiliency, security, security information correlation, text analysis, vulnerability detection |
Abstract | Protecting Critical Infrastructures (CIs) against contemporary cyber attacks has become a crucial as well as complex task. Modern attack campaigns, such as Advanced Persistent Threats (APTs), leverage weaknesses in the organization's business processes and exploit vulnerabilities of several systems to hit their target. Although their life-cycle can last for months, these campaigns typically go undetected until they achieve their goal. They usually aim at performing data exfiltration, cause service disruptions and can also undermine the safety of humans. Novel detection techniques and incident handling approaches are therefore required, to effectively protect CI's networks and timely react to this type of threats. Correlating large amounts of data, collected from a multitude of relevant sources, is necessary and sometimes required by national authorities to establish cyber situational awareness, and allow to promptly adopt suitable countermeasures in case of an attack. In this paper we propose three novel methods for security information correlation designed to discover relevant insights and support the establishment of cyber situational awareness. |
URL | http://ieeexplore.ieee.org/document/7906940/ |
DOI | 10.1109/PST.2016.7906940 |
Citation Key | settanni_correlating_2016 |
- feature extraction
- vulnerability detection
- text analysis
- security information correlation
- security
- Resiliency
- pubcrawl
- Metrics
- Mathematical model
- Joining processes
- information correlation
- Human Factors
- Human behavior
- Compositionality
- Europe
- Data Exfiltration
- cyber situational awareness
- cyber incidents handling
- cyber incident information correlation
- cyber attack
- critical infrastructures
- Critical Infrastructure Protection
- critical infrastructure
- Correlation
- computer network security