PWNJUTSU: A Dataset and a Semantics-Driven Approach to Retrace Attack Campaigns - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Article Dans Une Revue IEEE Transactions on Network and Service Management Année : 2022

PWNJUTSU: A Dataset and a Semantics-Driven Approach to Retrace Attack Campaigns

Résumé

Identifying patterns in the modus operandi of attackers is an essential requirement in the study of Advanced Persistent Threats. Previous studies have been hampered by the lack of accurate, relevant, and representative datasets of current threats. System logs and network traffic captured during attacks on real companies' information systems are the best data sources to build such datasets. Unfortunately, for apparent reasons of companies' reputation, privacy, and security, such data is seldom available. This article proposes an alternative approach to such issues involved with collecting data. It first presents a formal model of an attacker's tactical progression during their network propagation phase. Such a progression is expressed according to the attacker's state, called muSE, which specifies their propagation area, collected secrets, and knowledge of the environment. The new model wields the operational semantics of attack techniques proposed in this article. The semantics formally define a transition relation between attackers' states. Hence, it can be used to describe an entire attack scenario. This formalization allows the ability to describe the PWNJUTSU experiment unequivocally. In this experiment, 22 Red Teamers attacked the vulnerable infrastructure to compromise machines and steal secret flags. Each Red Teamer operated on a dedicated instance. Sensors captured system logs and network traffic on each of these instances. This article's second contribution is the public release of the PWNJUTSU dataset.
Fichier principal
Vignette du fichier
PWNJUTSU - A dataset and a semantics-driven approach to retrace attack campaigns.pdf (409.63 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03694719 , version 1 (14-06-2022)

Identifiants

Citer

Aimad Berady, Mathieu Jaume, Valérie Viet Triem Tong, Gilles Guette. PWNJUTSU: A Dataset and a Semantics-Driven Approach to Retrace Attack Campaigns. IEEE Transactions on Network and Service Management, 2022, Special Issue on Recent Advances in Network Security Management, 19 (4), pp.5252-5264. ⟨10.1109/TNSM.2022.3183476⟩. ⟨hal-03694719⟩
701 Consultations
780 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More