• DocumentCode
    166659
  • Title

    Targeted Attack Prevention at Early Stage

  • Author

    Chia-Mei Chen ; Peng-Yu Yang ; Ya-Hui Ou ; Han-Wei Hsiao

  • Author_Institution
    Dept. of Inf. Manage., Nat. Sun Yet-sen Univ., Kaohsiung, Taiwan
  • fYear
    2014
  • fDate
    13-16 May 2014
  • Firstpage
    866
  • Lastpage
    870
  • Abstract
    Targeted cyber attacks play a critical role in disrupting network infrastructure and information privacy. Based on the incident investigation, Intelligence gathering is the first phase of such attacks. To evade detection, hacker may make use of botnet, a set of zombie machines, to gain the access of a target and the zombies send the collected results back to the hacker. Even though the zombies would be blocked by detection system, the hacker, using the access information obtained from the botnet, would login the target from another machine without being noticed by the detection system. Such information gathering tactic can evade detection and the hacker grants the initial access to the target. The proposed defense system analyzes multiple logs from the network and extracts the reconnaissance attack sequences related to targeted attacks. State-based model is adopted to model the steps of the above early phase attack performed by multiple scouts and an intruder and such attack events in a long time frame becomes significant in the state-aware model. The results show that the proposed system can identify the attacks at the early stage efficiently to prevent further damage in the networks.
  • Keywords
    authorisation; data privacy; invasive software; ubiquitous computing; botnet; cyber attack; information privacy; intelligence gathering; network infrastructure; state-based model; targeted attack prevention; Computer hacking; Hidden Markov models; IP networks; Joints; Reconnaissance; Servers; intrusion detection; pervasive computing; targeted attacks;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications Workshops (WAINA), 2014 28th International Conference on
  • Conference_Location
    Victoria, BC
  • Print_ISBN
    978-1-4799-2652-7
  • Type

    conf

  • DOI
    10.1109/WAINA.2014.134
  • Filename
    6844748