DocumentCode
3245051
Title
A Framework of Attacker Centric Cyber Attack Behavior Analysis
Author
Xuena Peng ; Hong Zhao
Author_Institution
Univ. Shenyang, Shenyang
fYear
2007
fDate
24-28 June 2007
Firstpage
1449
Lastpage
1454
Abstract
Cyber attack behavior analysis can be roughly classified as "network centric" and "attacker centric" approaches. Compared with traditional "network centric" approach, the keys to implement "attacker centric" approach are to investigate the attacker relationship as while as tracking attackers. Current "attacker centric" approach researches mainly focus on single attacker centric behavior analysis, but overlook the attacker relationship and its impact on attack behavior analysis. This paper is mainly coping with such issues. In this paper, the framework of attacker centric behavior analysis is proposed. As key technique, the principles of choosing desirable attacker set are discussed, the concepts of attacker group and group member are introduced, and the corresponding attacker group recognition algorithms are also proposed. Finally, based on the proposed approaches, a prototype system CABAS is developed and evaluated under DARPA 2000 intrusion detection evaluation datasets. The experimental results show that our approach has potential in analyzing complex cooperative attacks.
Keywords
security of data; attacker centric cyber attack behavior analysis; attacker group recognition algorithms; group member; network centric; Communications Society; Data security; Forensics; Image analysis; Intrusion detection; Pattern analysis; Pattern matching; Protection; Prototypes; Software prototyping;
fLanguage
English
Publisher
ieee
Conference_Titel
Communications, 2007. ICC '07. IEEE International Conference on
Conference_Location
Glasgow
Print_ISBN
1-4244-0353-7
Type
conf
DOI
10.1109/ICC.2007.243
Filename
4288914
Link To Document