CRNov 16, 2020

MAAC: Novel Alert Correlation Method To Detect Multi-step Attack

arXiv:2011.07793v2
Originality Incremental advance
AI Analysis

This addresses the challenge for security analysts of manually analyzing overwhelming alerts from traditional intrusion detection systems to uncover complex attacks.

The paper tackles the problem of detecting multi-step cyber attacks by proposing MAAC, a system that correlates alerts from different sources using alert semantics and attack stages. Evaluation on real-world datasets shows MAAC reduces alerts by 90% and successfully identifies attack paths.

With the continuous improvement of attack methods, there are more and more distributed, complex, targeted attacks in which the attackers use combined attack methods to achieve the purpose. Advanced cyber attacks include multiple stages to achieve the ultimate goal. Traditional intrusion detection systems such as endpoint security management tools, firewalls, and other monitoring tools generate a large number of alerts during the attack. These alerts include attack clues, as well as many false positives unrelated to attacks. Security analysts need to analyze a large number of alerts and find useful clues from them and reconstruct attack scenarios. However, most traditional security monitoring tools cannot correlate alerts from different sources, so many multi-step attacks are still completely unnoticed, requiring manual analysis by security analysts like finding a needle in a haystack. We propose MAAC, a multi-step attack alert correlation system, which reduces repeated alerts and combines multi-step attack paths based on alert semantics and attack stages. The evaluation results of the real-world datasets show that MAAC can effectively reduce the alerts by 90\% and find attack paths from a large number of alerts.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes