跳到主要导航 跳到搜索 跳到主要内容

Efficient discovery of abnormal event sequences in enterprise security systems

  • Boxiang Dong*
  • , Zhengzhang Chen
  • , Hui Wang
  • , Lu An Tang
  • , Kai Zhang
  • , Ying Lin
  • , Zhichun Li
  • , Haifeng Chen
  • *此作品的通讯作者
  • NEC Corporation
  • Montclair State University
  • Stevens Institute of Technology
  • Temple University
  • University of Washington

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Intrusion detection system (IDS) is an important part of enterprise security system architecture. In particular, anomaly-based IDS has been widely applied to detect single abnormal process events that deviate from the majority. However, intrusion activity usually consists of a series of low-level heterogeneous events. The gap between low-level process events and high-level intrusion activities makes it particularly challenging to identify process events that are truly involved in a real malicious activity, and especially considering the massive "noisy" events filling the event sequences. Hence, the existing work that focus on detecting single events can hardly achieve high detection accuracy. In this work, we formulate a novel problem in intrusion detection - suspicious event sequence discovery, and propose GID, an efficient graph-based intrusion detection technique that can identify abnormal event sequences from massive heterogeneous process traces with high accuracy. We fully implement GID and deploy it into a real-world enterprise security system, and it greatly helps detect the advanced threats and optimize the incident response. Executing GID on both static and streaming data shows that GID is efficient (processes about 2 million records per minute) and accurate for intrusion detection.

源语言英语
主期刊名CIKM 2017 - Proceedings of the 2017 ACM Conference on Information and Knowledge Management
出版商Association for Computing Machinery
707-715
页数9
ISBN(电子版)9781450349185
DOI
出版状态已出版 - 6 11月 2017
已对外发布
活动26th ACM International Conference on Information and Knowledge Management, CIKM 2017 - Singapore, 新加坡
期限: 6 11月 201710 11月 2017

丛书

姓名International Conference on Information and Knowledge Management, Proceedings
Part F131841

会议

会议26th ACM International Conference on Information and Knowledge Management, CIKM 2017
国家/地区新加坡
Singapore
时期6/11/1710/11/17

学术指纹

探究 'Efficient discovery of abnormal event sequences in enterprise security systems' 的科研主题。它们共同构成独一无二的学术指纹。

引用此