【24h】

METAL - A Tool for Extracting Attack Manifestations

机译:金属-提取攻击表现的工具

获取原文
获取原文并翻译 | 示例

摘要

As manual analysis of attacks is time consuming and requires expertise, we developed a partly automated tool for extracting manifestations of intrusive behaviour from audit records, METAL (Manifestation Extraction Tool for Analysis of Logs). The tool extracts changes in audit data that are caused by an attack. The changes are determined by comparing data generated during normal operation to data generated during a successful attack. METAL identifies all processes that may be affected by the attack and the specific system call sequences, arguments and return values that are changed by the attack and makes it possible to analyse many attacks in a reasonable amount of time. Thus it is quicker and easier to find groups of attacks with similar properties and the automation of the process makes attack analysis considerably easier. We tested the tool in analyses of five different attacks and found that it works well, is considerably less time consuming and gives a better overview of the attacks than manual analysis.
机译:由于手动进行攻击分析非常耗时且需要专业知识,因此我们开发了一种半自动化工具,用于从审计记录中提取入侵行为的表现形式,METAL(用于日志分析的表现提取工具)。该工具提取由攻击引起的审核数据更改。通过将正常操作期间生成的数据与成功攻击期间生成的数据进行比较来确定更改。 METAL可以识别可能受到攻击影响的所有进程,以及特定的系统调用序列,参数和受攻击改变的返回值,并可以在合理的时间内分析许多攻击。因此,查找具有相似属性的攻击组变得更快,更容易,并且流程的自动化使攻击分析变得相当容易。我们在分析五种不同攻击的过程中测试了该工具,发现与手动分析相比,该工具运行良好,耗时少且对攻击的概述更好。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号