Towards Reconstructing Multi-Step Cyber Attacks in Modern Cloud Environments with Tripwires

09/25/2020
by   Mario Kahlhofer, et al.
0

Rapidly-changing cloud environments that consist of heavily interconnected components are difficult to secure. Existing solutions often try to correlate many weak indicators to identify and reconstruct multi-step cyber attacks. The lack of a true, causal link between most of these indicators still leaves administrators with a lot of false-positives to browse through. We argue that cyber deception can improve the precision of attack detection systems, if used in a structured, and automatic way, i.e., in the form of so-called tripwires that ultimately span an attack graph, which assists attack reconstruction algorithms. This paper proposes an idea for a framework that combines cyber deception, automatic tripwire injection and attack graphs, which eventually enables us to reconstruct multi-step cyber attacks in modern cloud environments.

READ FULL TEXT

page 1

page 2

research
06/14/2020

Launching Stealth Attacks using Cloud

Cloud computing offers users scalable platforms and low resource cost. A...
research
10/13/2018

False Data Injection Cyber-Attack Detection

State estimation estimates the system condition in real-time and provide...
research
11/20/2022

On Holistic Multi-Step Cyberattack Detection via a Graph-based Correlation Approach

While digitization of distribution grids through information and communi...
research
03/06/2023

Resource-aware Cyber Deception in Cloud-Native Environments

Cyber deception can be a valuable addition to traditional cyber defense ...
research
07/26/2023

ICCPS: Impact discovery using causal inference for cyber attacks in CPSs

We propose a new method to quantify the impact of cyber attacks in Cyber...
research
10/27/2020

Generalized Insider Attack Detection Implementation using NetFlow Data

Insider Attack Detection in commercial networks is a critical problem th...

Please sign up or login with your details

Forgot password? Click here to reset