DocumentCode :
3402710
Title :
Statistical detection of malicious web sites through time proximity to existing detection events
Author :
Kent, Alexander D. ; Liebrock, Lorie M.
Author_Institution :
Los Alamos Nat. Lab., Los Alamos, NM, USA
fYear :
2013
fDate :
13-15 Aug. 2013
Firstpage :
192
Lastpage :
197
Abstract :
We present a novel method of combining and aggregating disparate computer security events with web browsing activity to produce new and extended intrusion information with low false positives. This method integrates web browsing and intrusion-related security events as an unevenly spaced time series, and then aggregates commonalities from these integrated events across a population of monitored computers. This aggregation enables not only increased validation and knowledge about known security events, but also reveals new and previously unknown activity of security concern with very low false positives. This source-oriented information enables more effective defensive measures and increased enterprise-wide security. Using data covering over 24,000 computers and spanning 6 months, we demonstrate the value of our approach. Most importantly, we show a data reduction from 6.4 billion web requests to just 19 from 10 Internet domains requiring a security analyst´s review given our real world data set.
Keywords :
Web sites; security of data; Internet domains; Web browsing activity; computer security events; detection events; enterprise wide security; extended intrusion information; intrusion related security events; malicious Web sites; security analyst; source oriented information; spaced time series; statistical detection; time proximity; Computers; HTML; Internet; Malware; Organizations; Time series analysis;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Resilient Control Systems (ISRCS), 2013 6th International Symposium on
Conference_Location :
San Francisco, CA
Type :
conf
DOI :
10.1109/ISRCS.2013.6623775
Filename :
6623775
Link To Document :
بازگشت