Understanding multistage attacks by attack-track based visualization of heterogeneous event streams

  • Authors:
  • S. Mathew;R. Giomundo;S. Upadhyaya;M. Sudit;A. Stotz

  • Affiliations:
  • SUNY at Buffalo, Buffalo, NY;SUNY at Buffalo, Buffalo, NY;SUNY at Buffalo, Buffalo, NY;SUNY at Buffalo, Buffalo, NY;SUNY at Buffalo, Buffalo, NY

  • Venue:
  • Proceedings of the 3rd international workshop on Visualization for computer security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we present a method of handling the visualization of hetereogeneous event traffic that is generated by intrusion detection sensors, log files and other event sources on a computer network from the point of view of detecting multistage attack paths that are of importance. We perform aggregation and correlation of these events based on their semantic content to generate Attack Tracks that are displayed to the analyst in real-time. Our tool, called the Event Correlation for Cyber-Attack Recognition System (EC-CARS) enables the analyst to distinguish and separate an evolving multistage attack from the thousands of events generated on a network. We focus here on presenting the environment and framework for multistage attack detection using ECCARS along with screenshots that demonstrate its capabilities.