Complex network attacks represented by APTs are difficult to detect due to their stealthy attack methods and long attack durations. Meanwhile, traditional threat detection systems generate a large number of false positives, eventually overwhelming security analysts and making it impossible to focus on the truly important security threats. We propose Sky-eye, a complex network attack detection system based on network attack chain, which effectively utilizes data source analysis to summarize simple attack behaviors into attack subgraphs, and then divides the attack stages according to the network attack chain to aggregate attack subgraphs located in the same attack chain into attack events, thereby achieving the purpose of reducing false positives and analysis pressure. From modeling to detection, the design of Sky-eye is specifically tailored for the unique characteristics of multi-stage complex attacks. Sky-eye extracts provenance graphs that offer rich contextual and historical insights through efficient yet comprehensive graph analysis, enabling the identification of covert abnormal activities without relying on predefined attack signatures. Our evaluation results demonstrate that Sky-eye surpasses existing state-of-the-art APT detection systems and excels in accurately extracting attack events.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Sky-Eye: Detect Multi-stage Cyber Attacks at the Bigger Picture

  • Pengcheng Bi,
  • Qi Wang,
  • Zhuohang Lv,
  • Xiaochun Yun,
  • Tianning Zang

摘要

Complex network attacks represented by APTs are difficult to detect due to their stealthy attack methods and long attack durations. Meanwhile, traditional threat detection systems generate a large number of false positives, eventually overwhelming security analysts and making it impossible to focus on the truly important security threats. We propose Sky-eye, a complex network attack detection system based on network attack chain, which effectively utilizes data source analysis to summarize simple attack behaviors into attack subgraphs, and then divides the attack stages according to the network attack chain to aggregate attack subgraphs located in the same attack chain into attack events, thereby achieving the purpose of reducing false positives and analysis pressure. From modeling to detection, the design of Sky-eye is specifically tailored for the unique characteristics of multi-stage complex attacks. Sky-eye extracts provenance graphs that offer rich contextual and historical insights through efficient yet comprehensive graph analysis, enabling the identification of covert abnormal activities without relying on predefined attack signatures. Our evaluation results demonstrate that Sky-eye surpasses existing state-of-the-art APT detection systems and excels in accurately extracting attack events.