Visible to the public An Attack Graph-Based On-Line Multi-Step Attack Detector

TitleAn Attack Graph-Based On-Line Multi-Step Attack Detector
Publication TypeConference Paper
Year of Publication2018
AuthorsAngelini, Marco, Bonomi, Silvia, Borzi, Emanuele, Pozzo, Antonella Del, Lenti, Simone, Santucci, Giuseppe
Conference NameProceedings of the 19th International Conference on Distributed Computing and Networking
PublisherACM
Conference LocationNew York, NY, USA
ISBN Number978-1-4503-6372-3
KeywordsAlert correlation, attack detection, Attack Graphs, Attack Visualization, composability, Metrics, Multi-step Attacks, pubcrawl, resilience, Resiliency
AbstractModern distributed systems are characterized by complex deployment designed to ensure high availability through replication and diversity, to tolerate the presence of failures and to limit the possibility of successful compromising. However, software is not free from bugs that generate vulnerabilities that could be exploited by an attacker through multiple steps. This paper presents an attack-graph based multi-step attack detector aiming at detecting a possible on-going attack early enough to take proper countermeasures through; a Visualization interfaced with the described attack detector presents the security operator with the relevant pieces of information, allowing a better comprehension of the network status and providing assistance in managing attack situations (i.e., reactive analysis mode). We first propose an architecture and then we present the implementation of each building block. Finally, we provide an evaluation of the proposed approach aimed at highlighting the existing trade-off between accuracy of the detection and detection time.
DOI10.1145/3154273.3154311
Citation Keyangelini_attack_2018