Predicting and Visualizing Lateral Movements Based on ATT&CK and Quantification Theory Type 3

IF 0.7 Q4 COMPUTER SCIENCE, INFORMATION SYSTEMS
Satoshi Okada, Yosuke Katano, Yukihiro Kozai, Takuho Mitsunaga
{"title":"Predicting and Visualizing Lateral Movements Based on ATT&CK and Quantification Theory Type 3","authors":"Satoshi Okada, Yosuke Katano, Yukihiro Kozai, Takuho Mitsunaga","doi":"10.4018/jcit.340722","DOIUrl":null,"url":null,"abstract":"When a cyber incident occurs, organizations need to identify the attack's impacts. They have to investigate potentially infected devices as well as certainly infected devices. However, as an organization's network expands, it is difficult to investigate all devices. In addition, the cybersecurity workforce shortage has risen, so organizations need to respond to incidents efficiently with limited human resources. To solve this problem, this paper proposes a tool to assist an incident response team. It can visualize ATT&CK techniques attacker used and, furthermore, detect lateral movements efficiently. The tool consists of two parts: a web application that extracts ATT&CK techniques from logs and a lateral movement detection system. The web application was implemented and could map the collected logs obtained from an actual Windows device to the ATT&CK matrix. Furthermore, actual lateral movements were performed in an experimental environment that imitated an organizational network, and the proposed detection system could detect them.","PeriodicalId":43384,"journal":{"name":"Journal of Cases on Information Technology","volume":null,"pages":null},"PeriodicalIF":0.7000,"publicationDate":"2024-03-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Cases on Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.4018/jcit.340722","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q4","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

When a cyber incident occurs, organizations need to identify the attack's impacts. They have to investigate potentially infected devices as well as certainly infected devices. However, as an organization's network expands, it is difficult to investigate all devices. In addition, the cybersecurity workforce shortage has risen, so organizations need to respond to incidents efficiently with limited human resources. To solve this problem, this paper proposes a tool to assist an incident response team. It can visualize ATT&CK techniques attacker used and, furthermore, detect lateral movements efficiently. The tool consists of two parts: a web application that extracts ATT&CK techniques from logs and a lateral movement detection system. The web application was implemented and could map the collected logs obtained from an actual Windows device to the ATT&CK matrix. Furthermore, actual lateral movements were performed in an experimental environment that imitated an organizational network, and the proposed detection system could detect them.
基于 ATT&CK 和量化理论的侧向移动预测和可视化 3 型
发生网络事件时,企业需要确定攻击的影响。他们必须调查可能受感染的设备和肯定受感染的设备。然而,随着企业网络的扩展,很难对所有设备进行调查。此外,网络安全人才短缺的问题日益突出,因此企业需要利用有限的人力资源高效地应对突发事件。为解决这一问题,本文提出了一种协助事件响应团队的工具。它可以直观地显示攻击者使用的 ATT&CK 技术,并能有效地检测横向移动。该工具由两部分组成:从日志中提取 ATT&CK 技术的网络应用程序和横向移动检测系统。网络应用程序已经完成,可以将从实际 Windows 设备中收集到的日志映射到 ATT&CK 矩阵。此外,还在模仿组织网络的实验环境中进行了实际的横向移动,所提议的检测系统可以检测到这些横向移动。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Journal of Cases on Information Technology
Journal of Cases on Information Technology COMPUTER SCIENCE, INFORMATION SYSTEMS-
CiteScore
2.60
自引率
0.00%
发文量
64
期刊介绍: JCIT documents comprehensive, real-life cases based on individual, organizational and societal experiences related to the utilization and management of information technology. Cases published in JCIT deal with a wide variety of organizations such as businesses, government organizations, educational institutions, libraries, non-profit organizations. Additionally, cases published in JCIT report not only successful utilization of IT applications, but also failures and mismanagement of IT resources and applications.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信