发表机构
Faculty of Computer Science and Mathematics, OTH Regensburg; Institute for Software Engineering and Programming Languages, Universität zu Lübeck; Accemic Technologies GmbH(雷根斯堡应用技术大学计算机科学与数学学院; 吕贝克大学软件工程与程序设计语言研究所; Accemic科技有限公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出结合软件与硬件监控的基于模型的方法,以提升控制流异常检测与攻击树识别的鲁棒性,解决攻击者通过伪装控制流逃避检测的问题,在认证服务示例中验证了该方案可提高诊断精度。
AI 中文摘要
提升系统抵御网络攻击能力的方法愈发重要。控制流监控为确保完整性和在运行时检测潜在异常提供了原则性基础。一旦检测到异常,所谓的攻击树可用于识别可能的攻击类型。然而,这种方法易受伪装攻击影响,攻击者会通过故意操纵系统观测到的控制流来逃避检测(及正确识别)。本文提出一种基于模型的方法,该方法通过结合软件与硬件监控的架构,提供更鲁棒的入侵检测和攻击识别。在该方法中,软件层面的观测指示可疑活动,而硬件层面的监控会单独对其进行更详细的检查,使攻击更难以伪装并逃避检测。我们以一个捕获现实故障模式的认证服务示例来说明该方法:软件层面的观测器发现了异常但看似无害的控制流偏差,将其映射到攻击树中的良性根本原因,但遗漏了真正的入侵。第二个独立的硬件控制流监控器观测实际的转移序列,从而将攻击树诊断从低严重性的配置或维护问题,变更为高置信度的代码注入或控制流劫持。在该场景中,所提出的控制流异常检测、基于攻击树的入侵识别与基于硬件的监控相结合的方案,不仅能提升异常检测能力,还能提高基于攻击树的网络攻击识别的诊断精度。
英文摘要
Methods to increase the resilience of systems to cyber-attacks become increasingly important. Control-flow monitoring provides a principled basis to ensure integrity and detect possible anomalies at run-time. Once anomalies have been detected, so-called attack trees can be used to identify possible types of attacks. However, this approach is vulnerable to camouflage, by which attackers try to evade detection (and correct identification) by deliberately manipulating also the system's observed control flow. In this paper, we outline a model-based approach that provides more robust intrusion detection and attack identification through an architecture that combines software- with hardware-based monitoring. In this approach, software-level observation indicates suspicious activities, while hardware-level monitoring checks them separately in more detail, making it much harder for attacks to camouflage themselves and go undetected. We illustrate the approach with an authentication-service example that captures a realistic failure mode: a software-level observer sees an anomalous but apparently harmless control-flow deviation, maps it to a benign root cause in an attack tree, but misses the true intrusion. A second, independent hardware control-flow monitor observes the actual transition sequence and thereby changes the attack-tree diagnosis from a low-severity configuration or maintenance issue to a high-confidence code-injection or control-flow hijack. In this scenario, the proposed combination of control-flow anomaly detection, attack-tree based intrusion identification, and hardware-based monitoring can improve not only anomaly detection, but also the diagnostic precision of attack-tree-based cyber-attack identification.
Comments14 pages