Skip to main navigation Skip to search Skip to main content

Attack scenario recognition through heterogeneous event stream analysis

  • SUNY Buffalo

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Stealthy, goal-oriented multistage attacks are difficult to detect since they often consist of specific attack steps that do not cause significant variations in the statistical distributions of data streams. We present an approach for attack scenario detection and recognition that is based on analyzing data streams from multiple heterogeneous sensors. Events captured from these sensors are used to generate high-dimensional state vectors that characterize overall system-wide activity. Monitoring the time series of these state vectors through Principal Component Analysis forms the basis of an anomaly detection technique for real-time scenario detection. Data traffic from a real network that emulates a military intelligence network is used to test and validate this approach. Results indicate that our approach is both effective and has low computational requirements, making it a candidate for practical implementation.

Original languageEnglish
Title of host publicationMILCOM 2009 - 2009 IEEE Military Communications Conference
DOIs
StatePublished - 2009
Event2009 IEEE Military Communications Conference, MILCOM 2009 - Boston, MA, United States
Duration: Oct 18 2009Oct 21 2009

Publication series

NameProceedings - IEEE Military Communications Conference MILCOM

Conference

Conference2009 IEEE Military Communications Conference, MILCOM 2009
Country/TerritoryUnited States
CityBoston, MA
Period10/18/0910/21/09

Fingerprint

Dive into the research topics of 'Attack scenario recognition through heterogeneous event stream analysis'. Together they form a unique fingerprint.

Cite this