DocumentCode :
2408484
Title :
The attackers´ potential influence on the tactical assessments produced by standard alert correlation systems
Author :
Neville, Stephen W.
Author_Institution :
Dept. of Electr. & Comput. Eng., Victoria Univ., BC, Canada
fYear :
2005
fDate :
6 Nov. 2005
Firstpage :
61
Lastpage :
66
Abstract :
This work shows that knowledgeable attackers can influence the tactical assessments output by INFOSEC alert correlation systems solely through manipulating the timing characteristics of their attacks. The approach taken is to assume that the defender´s goal is to thwart attackers by enact optimal tactical responses. It is then shown that, even in an idealized environment, the defender has no guarantee that the correlation system´s estimates of the enacted attacks are correct. A theoretical path always exists by which the attacker can influence the contents of the correlation system´s low-level alert clusters. As these low-level clusters form the basis of all higher level analyses, this is sufficient to show that the attacker has influence over the tactical assessments reported by correlation systems. In essence, the attackers can cause the defender to mis-correlate an attack´s generated INFOSEC alerts in a manner which can go undetected and is to the attacker´s advantage. This capability is shown to hinge on there being attacks whose identification requires the analysis of shared alerts (i.e., alerts generated by two or more distinct attacks).
Keywords :
military communication; telecommunication networks; telecommunication security; network security; standard alert correlation systems; tactical assessments; timing characteristics; Councils; Fasteners; Game theory; Large-scale systems; Performance analysis; Pressing; Production; Telecommunication traffic; Testing; Traffic control;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Secure Network Protocols, 2005. (NPSec). 1st IEEE ICNP Workshop on
Print_ISBN :
0-7803-9427-5
Type :
conf
DOI :
10.1109/NPSEC.2005.1532055
Filename :
1532055
Link To Document :
بازگشت