The growing sophistication of cyber threats has raised the importance of providing a proper level of cybersecurity to networks and interconnected devices. Process mining provides methods to analyse sequences of activities performed by operators or programs on such devices to detect cyber-attacks from a novel perspective, i.e., as continuous processes composed of observable system events. However, processes like that, especially in domains such as the cybersecurity of the Internet of Things (IoT) or network devices, are usually characterised by large variability and complexity, which makes them difficult to model. We propose a method called ThreatTrace for simplifying and creating embeddings of complex process traces that can often be observed in event logs from such domains. The novelty of ThreatTrace stems from integrating process mining techniques into the cyber-threats discovery workflow. It combines process trace abstraction, embedding, and soft clustering to generate compact process variant representations that preserve information about patterns of interest, e.g., traces of potential cyber-attacks. Our experiments show that such information extracted from event logs improves the detection of cyber-attacks over approaches that do not consider the process perspective, particularly in the context of IoT device and network cybersecurity.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

ThreatTrace: Cyber-Attack Detection Through Trace Abstraction and Soft Clustering

  • Andrzej Janusz,
  • Savandi Kalukapuge,
  • Moe Thandar Wynn

摘要

The growing sophistication of cyber threats has raised the importance of providing a proper level of cybersecurity to networks and interconnected devices. Process mining provides methods to analyse sequences of activities performed by operators or programs on such devices to detect cyber-attacks from a novel perspective, i.e., as continuous processes composed of observable system events. However, processes like that, especially in domains such as the cybersecurity of the Internet of Things (IoT) or network devices, are usually characterised by large variability and complexity, which makes them difficult to model. We propose a method called ThreatTrace for simplifying and creating embeddings of complex process traces that can often be observed in event logs from such domains. The novelty of ThreatTrace stems from integrating process mining techniques into the cyber-threats discovery workflow. It combines process trace abstraction, embedding, and soft clustering to generate compact process variant representations that preserve information about patterns of interest, e.g., traces of potential cyber-attacks. Our experiments show that such information extracted from event logs improves the detection of cyber-attacks over approaches that do not consider the process perspective, particularly in the context of IoT device and network cybersecurity.