Detecting Targeted Attacks by Risk Evaluation
targeted attack, feature reduce, rough set theory, intrusion detection system
More recently, the problems of targeted attack have been the major subject of study in the fields of network attack research due to the increase of network usage. In the past few years, study in network attacks analysis has shifted its focus from random attack to targeted attack, such as DDoS, APT, and Ransomware. The features of targeted attack are probing the vulnerable hosts of targeted enterprises for a long-term period, entice someone by several methods such as social network, malicious websites, C&C then execute attack behaviors such as intrusion of important system by malware to paralyze the service or steal secret data.
Computers are becoming a part of our everyday life, thus the internet data are becoming larger day by day, which makes administering such gigantic data a challenging task. It is becoming more difficult to analyze the malicious behaviors in a long-term period. Accordingly, this study associated multiple data source to assemble gigantic log data before filtering malicious features to recognize the behavior module when hackers attack the vulnerable systems. First by extracting the correct feature sets by two-stage feature reduction. The first stage, rough set theory is utilized to extract the critical characteristics to find out the feature sets of targeted attacks. The second stage, the chi-square test is employed to confirm the applicable to judge the targeted attack. Then, risk values of each stage are calculated to early alert the administrator to estimate the hazardous IP address. The experiment shows that two-stage feature reduction improves the effect of filtering to enhance the detection rate. By accurately measuring risk for enterprise networks, our system allows network defenders to discover the most critical threats and select the most effective countermeasure.
目次 Table of Contents
目 錄
中文摘要 ii
Abstract iii
第一章 緒論 1
1.1 研究動機 2
1.2 研究目的 3
第二章 相關文獻 5
2.1 目標式攻擊 5
2.2 約略集合理論 8
2.3 卡方檢定 11
2.4 風險評估 11
2.5. 屬性折減 12
第三章 研究方法 13
3.1擷取特徵 14
3.2 驗證特徵集合 16
3.3 風險值計算 19
3.4總風險值 23
第四章 實驗與結果 25
4.1 Experiment 1: 約略集合理論 25
4.1.1 實驗結果分析 26
1.2 Experiment 2:卡方檢定 27
4.2.1. 實驗結果分析 31
1.3 Experiment 3: 利用風險值計算作為可疑名單的基礎 31
4.3.1 Experiment 3A: 單一特徵集合偵測率 31
4.3.2 Experiment 3B: 特徵集合組合後的偵測率 36
4.3.3 Experiment 3C: Test data 偵測率 40
4.4 Experiment4: 驗證新攻擊 45
4.5 對照SVM分類器的比較 46
第五章 結論 50
參考文獻 51
參考文獻 References
