• DocumentCode
    3245051
  • Title

    A Framework of Attacker Centric Cyber Attack Behavior Analysis

  • Author

    Xuena Peng ; Hong Zhao

  • Author_Institution
    Univ. Shenyang, Shenyang
  • fYear
    2007
  • fDate
    24-28 June 2007
  • Firstpage
    1449
  • Lastpage
    1454
  • Abstract
    Cyber attack behavior analysis can be roughly classified as "network centric" and "attacker centric" approaches. Compared with traditional "network centric" approach, the keys to implement "attacker centric" approach are to investigate the attacker relationship as while as tracking attackers. Current "attacker centric" approach researches mainly focus on single attacker centric behavior analysis, but overlook the attacker relationship and its impact on attack behavior analysis. This paper is mainly coping with such issues. In this paper, the framework of attacker centric behavior analysis is proposed. As key technique, the principles of choosing desirable attacker set are discussed, the concepts of attacker group and group member are introduced, and the corresponding attacker group recognition algorithms are also proposed. Finally, based on the proposed approaches, a prototype system CABAS is developed and evaluated under DARPA 2000 intrusion detection evaluation datasets. The experimental results show that our approach has potential in analyzing complex cooperative attacks.
  • Keywords
    security of data; attacker centric cyber attack behavior analysis; attacker group recognition algorithms; group member; network centric; Communications Society; Data security; Forensics; Image analysis; Intrusion detection; Pattern analysis; Pattern matching; Protection; Prototypes; Software prototyping;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications, 2007. ICC '07. IEEE International Conference on
  • Conference_Location
    Glasgow
  • Print_ISBN
    1-4244-0353-7
  • Type

    conf

  • DOI
    10.1109/ICC.2007.243
  • Filename
    4288914