论文标题
旨在通过Tripwires重建现代云环境中的多步网络攻击
Towards Reconstructing Multi-Step Cyber Attacks in Modern Cloud Environments with Tripwires
论文作者
论文摘要
由重大互连组件组成的快速变化的云环境很难确保。现有的解决方案通常试图将许多弱指标相关联,以识别和重建多步网络攻击。大多数这些指标之间缺乏真正的因果关系仍然使管理员浏览很多假阳性。我们认为,如果以结构化的和自动的方式使用,网络欺骗可以提高攻击检测系统的精度,即以所谓的TripWires的形式最终跨越攻击图,从而有助于攻击重建算法。本文提出了一个结合网络欺骗,自动Tripwire注射和攻击图的框架的想法,最终使我们能够在现代云环境中重建多步网络攻击。
Rapidly-changing cloud environments that consist of heavily interconnected components are difficult to secure. Existing solutions often try to correlate many weak indicators to identify and reconstruct multi-step cyber attacks. The lack of a true, causal link between most of these indicators still leaves administrators with a lot of false-positives to browse through. We argue that cyber deception can improve the precision of attack detection systems, if used in a structured, and automatic way, i.e., in the form of so-called tripwires that ultimately span an attack graph, which assists attack reconstruction algorithms. This paper proposes an idea for a framework that combines cyber deception, automatic tripwire injection and attack graphs, which eventually enables us to reconstruct multi-step cyber attacks in modern cloud environments.