• DocumentCode
    2130748
  • Title

    Experiences and Challenges in Enhancing Security Information and Event Management Capability Using Unsupervised Anomaly Detection

  • Author

    Asanger, Stefan ; Hutchison, Andrew

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Cape Town, Cape Town, South Africa
  • fYear
    2013
  • fDate
    2-6 Sept. 2013
  • Firstpage
    654
  • Lastpage
    661
  • Abstract
    Security Information and Event Management (SIEM) systems are important components of security and threat management in enterprises. To compensate for the shortcomings of rule-based correlation in this field, there has been an increasing demand for advanced anomaly detection techniques. Such implementations, where prior training data is not required, have been described previously. In this paper, we focus on the requirements for such a system and provide insight into how diverse security events need to be parsed, unified and preprocessed to meet the requirements of unsupervised anomaly detection algorithms. Specific focus is given to the detection of suspicious authentication attempts, password guessing attacks and unusual user account activities in a large-scale Microsoft Windows domain network. In the course of this paper we analyze a comprehensive dataset of 15 million Windows security events from various perspectives using the k-nearest neighbor algorithm. Key considerations on how to effectively apply anomaly detection are proposed in order to produce accurate and convincing results. The effectiveness of our approach is discussed using sample anomalies that were detected in the analyzed data.
  • Keywords
    authorisation; data analysis; knowledge based systems; unsupervised learning; user interfaces; SIEM; Windows security events; advanced anomaly detection techniques; data analysis; diverse security events; k-nearest neighbor algorithm; large-scale Microsoft Windows domain network; password guessing attack detection; rule-based correlation; security information and event management systems; suspicious authentication attempt detection; threat management; unsupervised anomaly detection algorithm; unusual user account activity detection; Authentication; Servers; Training data; Vectors; Workstations; Account Logon; Anomaly Detection; Behavior Profiling; Logon/Logoff; SIEM; Windows Security Events;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2013 Eighth International Conference on
  • Conference_Location
    Regensburg
  • Type

    conf

  • DOI
    10.1109/ARES.2013.86
  • Filename
    6657302