Visible to the public Correlating cyber incident information to establish situational awareness in Critical Infrastructures

TitleCorrelating cyber incident information to establish situational awareness in Critical Infrastructures
Publication TypeConference Paper
Year of Publication2016
AuthorsSettanni, G., Shovgenya, Y., Skopik, F., Graf, R., Wurzenberger, M., Fiedler, R.
Conference Name2016 14th Annual Conference on Privacy, Security and Trust (PST)
Date Publisheddec
Keywordscompositionality, computer network security, Correlation, critical infrastructure, critical infrastructure protection, critical infrastructures, cyber attack, cyber incident information correlation, cyber incidents handling, cyber situational awareness, Data Exfiltration, Europe, feature extraction, Human Behavior, human factors, information correlation, Joining processes, Mathematical model, Metrics, pubcrawl, Resiliency, security, security information correlation, text analysis, vulnerability detection
Abstract

Protecting Critical Infrastructures (CIs) against contemporary cyber attacks has become a crucial as well as complex task. Modern attack campaigns, such as Advanced Persistent Threats (APTs), leverage weaknesses in the organization's business processes and exploit vulnerabilities of several systems to hit their target. Although their life-cycle can last for months, these campaigns typically go undetected until they achieve their goal. They usually aim at performing data exfiltration, cause service disruptions and can also undermine the safety of humans. Novel detection techniques and incident handling approaches are therefore required, to effectively protect CI's networks and timely react to this type of threats. Correlating large amounts of data, collected from a multitude of relevant sources, is necessary and sometimes required by national authorities to establish cyber situational awareness, and allow to promptly adopt suitable countermeasures in case of an attack. In this paper we propose three novel methods for security information correlation designed to discover relevant insights and support the establishment of cyber situational awareness.

URLhttp://ieeexplore.ieee.org/document/7906940/
DOI10.1109/PST.2016.7906940
Citation Keysettanni_correlating_2016