• DocumentCode
    3147131
  • Title

    A defense-centric taxonomy based on attack manifestations

  • Author

    Killourhy, Kevin S. ; Maxion, Roy A. ; Tan, Kymie M C

  • Author_Institution
    Dept. of Comput. Sci., Carnegie Mellon Univ., Pittsburgh, PA, USA
  • fYear
    2004
  • fDate
    28 June-1 July 2004
  • Firstpage
    102
  • Lastpage
    111
  • Abstract
    Many classifications of attacks have been tendered, often in taxonomic form, A common basis of these taxonomies is that they have been framed from the perspective of an attacker - they organize attacks with respect to the attacker´s goals, such as privilege elevation from user to root (from the well known Lincoln taxonomy). Taxonomies based on attacker goals are attack-centric; those based on defender goals are defense-centric. Defenders need a way of determining whether or not their detectors will detect a given attack. It is suggested that a defense-centric taxonomy would suit this role more effectively than an attack-centric taxonomy. This paper presents a new, defense-centric attack taxonomy, based on the way that attacks manifest as anomalies in monitored sensor data. Unique manifestations, drawn from 25 attacks, were used to organize the taxonomy, which was validated through exposure to an intrusion-detection system, confirming attack detect ability. The taxonomy´s predictive utility was compared against that of a well-known extant attack-centric taxonomy. The defense-centric taxonomy is shown to be a more effective predictor of a detector´s ability to detect specific attacks, hence informing a defender that a given detector is competent against an entire class of attacks.
  • Keywords
    authorisation; computer crime; Lincoln taxonomy; attack classification; attack detectability; attack manifestations; attack-centric taxonomy; defense-centric taxonomy; intrusion detection; sensor data monitoring; Computer science; Detectors; Laboratories; Monitoring; Operating systems; Sensor systems; Taxonomy;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks, 2004 International Conference on
  • Print_ISBN
    0-7695-2052-9
  • Type

    conf

  • DOI
    10.1109/DSN.2004.1311881
  • Filename
    1311881