论文标题
通过基于图的相关方法进行整体多步网络攻击检测
On Holistic Multi-Step Cyberattack Detection via a Graph-based Correlation Approach
论文作者
论文摘要
尽管通过信息和通信技术数字化分销网格带来了许多好处,但它也增加了电网对严重的网络攻击的脆弱性。与传统的系统不同,对许多工业控制系统(例如电网)的攻击通常会在多个阶段发生,攻击者立即采取了几步以实现其目标。需要具有情境意识的检测机制来检测精心策划的攻击步骤,这是连贯攻击运动的一部分。为了为检测和预防此类攻击提供基础,本文借助于基于图形的网络智能数据库和警报相关方法来解决多个阶段网络攻击的检测。具体而言,我们提出了一种通过利用异质数据形成知识库并在生成的警报上采用基于模型的相关方法来检测多阶段攻击的方法,以识别网络中发生的多阶段网络攻击序列。我们通过在未来面向的电网飞行员中使用多阶段网络攻击运动的案例研究来研究所提出方法的检测质量。
While digitization of distribution grids through information and communications technology brings numerous benefits, it also increases the grid's vulnerability to serious cyber attacks. Unlike conventional systems, attacks on many industrial control systems such as power grids often occur in multiple stages, with the attacker taking several steps at once to achieve its goal. Detection mechanisms with situational awareness are needed to detect orchestrated attack steps as part of a coherent attack campaign. To provide a foundation for detection and prevention of such attacks, this paper addresses the detection of multi-stage cyber attacks with the aid of a graph-based cyber intelligence database and alert correlation approach. Specifically, we propose an approach to detect multi-stage attacks by leveraging heterogeneous data to form a knowledge base and employ a model-based correlation approach on the generated alerts to identify multi-stage cyber attack sequences taking place in the network. We investigate the detection quality of the proposed approach by using a case study of a multi-stage cyber attack campaign in a future-orientated power grid pilot.