Skip to main navigation Skip to search Skip to main content

Combining Dynamic and Static Attack Information for Attack Tracing and Event Correlation

  • Adel Alshamrani
  • , Ankur Chowdhary
  • , Oussama Mjihil
  • , Sowmya Myneni
  • , Dijiang Huang
  • Arizona State University
  • Hassan I University

Research output: Contribution to journalConference articlepeer-review

2 Citations (Scopus)

Abstract

Many sophisticated attacks, e.g. Advanced Persistent Threats (APTs), have emerged with a variety of different attack forms. APT employs a wide range of sophisticated reconnaissance and information-gathering tools, as well as attack tools and methods. The diversity and stealthiness of APT make it a challenging threat to current networking systems. The attackers are very skilled and try to hide in a system undetected for a long period of time with the incentive to steal and collect invaluable Current commonly used solutions (firewalls, Intrusion Detection Systems, proxies, etc.) show the limited efficiency of detecting APT. Thus, in this paper, we design a solution that is based on multi-source data combination to learn the adversarial behavior of suspicious users as well as to optimally select a proper countermeasure.

Original languageEnglish
Article number8647326
JournalProceedings - IEEE Global Communications Conference, GLOBECOM
DOIs
Publication statusPublished - 2018
Externally publishedYes
Event2018 IEEE Global Communications Conference, GLOBECOM 2018 - Abu Dhabi, United Arab Emirates
Duration: 9 Dec 201813 Dec 2018

Keywords

  • Advanced Persistent Threats
  • Attack Graph
  • Intrusion Detection Systems

Cite this