Attack Fingerprints based on the Activity and Event Network(AEN) Model

dc.contributor.authorNie, Chenyang
dc.date.accessioned2020-08-12T22:47:18Z
dc.date.available2020-08-12T22:47:18Z
dc.date.copyright2020en_US
dc.date.issued2020-08-12
dc.degree.departmentDepartment of Electrical and Computer Engineering
dc.degree.levelMaster of Engineering M.Eng.en_US
dc.description.abstractThe Activity and Event (AEN) graph is a new framework that enables capturing ongoing security-relevant activity and events occurring at a given organization using a large random time-varying graph model. The graph is generated by processing various network security logs, such as network packets, system logs, and intrusion detection alerts. In this report, we show how known attack methods can be captured generically using attack fingerprints based on the AEN graph. The fingerprints are constructed by identifying attack idiosyncrasies under the form of subgraphs that represent indicators of compromise (IOCs), and then encoded using PGQL queries. Among the many attack types, three main categories are implemented in our model: Probing, Denial of Service(DoS), and authentication breaches; Each category contains its common variations. The experimental evaluation of the fingerprints was carried using a combination of intrusion detection datasets and yielded very encouraging results.en_US
dc.description.scholarlevelGraduateen_US
dc.identifier.urihttp://hdl.handle.net/1828/11986
dc.language.isoenen_US
dc.rightsAvailable to the World Wide Weben_US
dc.subjectNetwork Attacken_US
dc.subjectIntrusion Detectionen_US
dc.subjectPort Scanen_US
dc.subjectGraph Databaseen_US
dc.subjectDDoSen_US
dc.titleAttack Fingerprints based on the Activity and Event Network(AEN) Modelen_US
dc.typeprojecten_US

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Nie_Chenyang_MEng_2020.pdf
Size:
2.87 MB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: