• DocumentCode
    2302259
  • Title

    Identifying Compromised Users in Shared Computing Infrastructures: A Data-Driven Bayesian Network Approach

  • Author

    Pecchia, Antonio ; Sharma, Aashish ; Kalbarczyk, Zbigniew ; Cotroneo, Domenico ; Iyer, Ravishankar K.

  • Author_Institution
    Dipt. di Inf. e Sist., Univ. degli Studi di Napoli Federico II, Naples, Italy
  • fYear
    2011
  • fDate
    4-7 Oct. 2011
  • Firstpage
    127
  • Lastpage
    136
  • Abstract
    The growing demand for processing and storage capabilities has led to the deployment of high-performance computing infrastructures. Users log into the computing infrastructure remotely, by providing their credentials (e.g., username and password), through the public network and using well-established authentication protocols, e.g., SSH. However, user credentials can be stolen and an attacker (using a stolen credential) can masquerade as the legitimate user and penetrate the system as an insider. This paper deals with security incidents initiated by using stolen credentials and occurred during the last three years at the National Center for Supercomputing Applications (NCSA) at the University of Illinois. We analyze the key characteristics of the security data produced by the monitoring tools during the incidents and use a Bayesian network approach to correlate (i) data provided by different security tools (e.g., IDS and Net Flows) and (ii) information related to the users´ profiles to identify compromised users, i.e., the users whose credentials have been stolen. The technique is validated with the real incident data. The experimental results demonstrate that the proposed approach is effective in detecting compromised users, while allows eliminating around 80% of false positives (i.e., not compromised user being declared compromised).
  • Keywords
    belief networks; security of data; NCSA; authentication protocols; data driven Bayesian network approach; national center for supercomputing applications; security incidents; shared computing infrastructures; stolen credentials; storage capabilities; Authentication; Bayesian methods; IP networks; Monitoring; Protocols; Vectors; Bayesian network; correlation; credential stealing; intrusion detection; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Reliable Distributed Systems (SRDS), 2011 30th IEEE Symposium on
  • Conference_Location
    Madrid
  • ISSN
    1060-9857
  • Print_ISBN
    978-1-4577-1349-1
  • Type

    conf

  • DOI
    10.1109/SRDS.2011.24
  • Filename
    6076770