Cybersecurity knowledge graph enabled attack chain detection for cyber-physical systems

COMPUTERS & ELECTRICAL ENGINEERING(2023)

引用 6|浏览30
暂无评分
摘要
The Cyber-Physical System covers a wide range of applications, many of which are involved in critical infrastructure, and the cybersecurity attacks on them become more and more threatening. Currently, most of the comprehensive analysis of compound attacks depend on the experience of security analysts. To improve the efficiency and accuracy of compound attack research, this paper introduces a knowledge graph into compound attack detection and constructs a cybersecurity knowledge graph based on the knowledge of known attacks. The cybersecurity knowledge graph can carry out correlation analysis on real-time data to restore the attack process. The main work of this paper is to construct the cybersecurity knowledge graph and to apply mining found compound attacks automatically. Besides, a multi-dimensional data association analysis algo-rithm based on dynamic clustering mechanism, and an attack chain complementation-pruning method based on optimal reaching path queries are proposed to solve the problem of low effi-ciency in correlation analysis caused by redundant data and the problem of missing and mis-understandings in the collection data. Experiments show that the cyber security knowledge graph construction method and attack chain optimization-pruning method proposed in this paper improve the accuracy and efficiency of attack chain mining.
更多
查看译文
关键词
Cyber-physical systems,Knowledge representation,Association analysis,Attack rule base,Compound attack chain complementation-pruning
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要