Journal on Communications ›› 2019, Vol. 40 ›› Issue (7): 57-66.doi: 10.11959/j.issn.1000-436x.2019142

• Papers • Previous Articles     Next Articles

Multi-step attack detection method based on network communication anomaly recognition

Ankang JU,Yuanbo GUO,Tao LI,Ziwei YE   

  1. Department of Cryptogram Engineering,Strategic Support Force Information Engineering University,Zhengzhou 450001,China
  • Revised:2019-05-22 Online:2019-07-25 Published:2019-07-30
  • Supported by:
    The National Natural Science Foundation of China(61501515)

Abstract:

In view of the characteristics of internal fixed business logic,inbound and outbound network access behavior,two classes and four kinds of abnormal behaviors were defined firstly,and then a multi-step attack detection method was proposed based on network communication anomaly recognition.For abnormal sub-graphs and abnormal communication edges detection,graph-based anomaly analysis and wavelet analysis method were respectively proposed to identify abnormal behaviors in network communication,and detect multi-step attacks through anomaly correlation analysis.Experiments are carried out on the DARPA 2000 data set and LANL data set to verify the results.The experimental results show that the proposed method can effectively detect and reconstruct multi-step attack scenarios.The proposed method can effectively monitor multi-step attacks including unknown feature types.It provides a feasible idea for detecting complex multi-step attack patterns such as APT.And the network communication graph greatly reduces the data size,it is suitable for large-scale enterprise network environments.

Key words: multi-step attack, network anomaly, communication graph, wavelet analysis

CLC Number: 

No Suggested Reading articles found!