DocumentCode :
3147131
Title :
A defense-centric taxonomy based on attack manifestations
Author :
Killourhy, Kevin S. ; Maxion, Roy A. ; Tan, Kymie M C
Author_Institution :
Dept. of Comput. Sci., Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear :
2004
fDate :
28 June-1 July 2004
Firstpage :
102
Lastpage :
111
Abstract :
Many classifications of attacks have been tendered, often in taxonomic form, A common basis of these taxonomies is that they have been framed from the perspective of an attacker - they organize attacks with respect to the attacker´s goals, such as privilege elevation from user to root (from the well known Lincoln taxonomy). Taxonomies based on attacker goals are attack-centric; those based on defender goals are defense-centric. Defenders need a way of determining whether or not their detectors will detect a given attack. It is suggested that a defense-centric taxonomy would suit this role more effectively than an attack-centric taxonomy. This paper presents a new, defense-centric attack taxonomy, based on the way that attacks manifest as anomalies in monitored sensor data. Unique manifestations, drawn from 25 attacks, were used to organize the taxonomy, which was validated through exposure to an intrusion-detection system, confirming attack detect ability. The taxonomy´s predictive utility was compared against that of a well-known extant attack-centric taxonomy. The defense-centric taxonomy is shown to be a more effective predictor of a detector´s ability to detect specific attacks, hence informing a defender that a given detector is competent against an entire class of attacks.
Keywords :
authorisation; computer crime; Lincoln taxonomy; attack classification; attack detectability; attack manifestations; attack-centric taxonomy; defense-centric taxonomy; intrusion detection; sensor data monitoring; Computer science; Detectors; Laboratories; Monitoring; Operating systems; Sensor systems; Taxonomy;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks, 2004 International Conference on
Print_ISBN :
0-7695-2052-9
Type :
conf
DOI :
10.1109/DSN.2004.1311881
Filename :
1311881
Link To Document :
بازگشت