Visible to the public Pattern Discovery in Intrusion Chains and Adversarial Movement

TitlePattern Discovery in Intrusion Chains and Adversarial Movement
Publication TypeConference Paper
Year of Publication2019
AuthorsAsadi, Nima, Rege, Aunshul, Obradovic, Zoran
Conference Name2019 International Conference on Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA)
Keywordsadversarial movement, composability, Computer crime, cyber security, cybercrimes, cybersecurity, data mining, data-driven analysis, decision making, intrusion chains, intrusion stages, Metrics, organisational aspects, pattern discovery, pubcrawl, resilience, Resiliency, situational awareness, social networking (online), social networks, time series, Time series analysis
AbstractCapturing the patterns in adversarial movement can present crucial insight into team dynamics and organization of cybercrimes. This information can be used for additional assessment and comparison of decision making approaches during cyberattacks. In this study, we propose a data-driven analysis based on time series analysis and social networks to identify patterns and alterations in time allocated to intrusion stages and adversarial movements. The results of this analysis on two case studies of collegiate cybersecurity exercises is provided as well as an analytical comparison of their behavioral trends and characteristics. This paper presents preliminary insight into complexities of individual and group level adversarial movement and decision-making as cyberattacks unfold.
DOI10.1109/CyberSA.2019.8899391
Citation Keyasadi_pattern_2019