Concept for real time attacker profiling with honeypots, by skill based attacker maturity model

Ádám Balogh, Máté Érsok,Anna Bánáti,László Erdődi

2024 IEEE 22nd World Symposium on Applied Machine Intelligence and Informatics (SAMI)(2024)

引用 0|浏览0
暂无评分
摘要
For modern IT infrastructures, it is essential to know not only the presence of an attack, but also the ability to trace its process, details and severity. The increasingly widespread security operational center approach makes this much easier, events logged by countless systems can be managed and processed centrally. In our article, starting from this principle, we develop a theoretical concept for an attacker maturity model, as well as its detection and classification method, based on the actions of an intruder. By the creation of a specific research purpose honeynet which simulates the network of a corporate environment, enough data can be collected, to analyze the attacker behavior. Based on our previous research, such system can greatly aid the work of security analysts by indicating the type of threat they are facing right from the start of an attack.
更多
查看译文
关键词
defensive deception,honeypot,measurement,indicator,attacker,maturity,SOC,cyber,security
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要