AI 中文总结
本研究提出基于主机的Stitch系统,利用可编程内核结合系统与网络级信息检测横向移动攻击,准确率较现有最优方案提升31%,误报率低,填补了相关检测方案的空白。
AI 中文摘要
基于边界的安全设备(如防火墙或入侵检测系统)对采用横向移动(pivoting)的现代攻击无效,攻击者通过受感染主机“横向移动”流量以获取原本无法访问的其他目标。由于中继流量具有合法外观,横向移动攻击极难检测。尽管此类攻击后果严重,但现有防御存在高处理延迟、低准确率或依赖全网参与等缺陷,导致不便甚至无效。本研究提出Stitch,一种基于主机的系统,利用可编程内核实时检测横向移动。通过观察主机流经的流量,Stitch采用进程追踪有效结合系统与网络级信息,连接入站与出站通信并识别其间的横向移动特征。在两项独立真实部署中,Stitch较现有最优横向移动防御准确率提升31%,最大误报率为0.006%,通过为网络中易受攻击的主机提供准确、轻量且独立的覆盖,填补了当前横向移动检测方案的空白。
英文摘要
Perimeter-based security appliances, such as firewalls or Intrusion Detection Systems, are ineffective against modern attacks that use pivoting, wherein attackers "pivot" traffic through compromised hosts to gain access to additional targets that would otherwise be inaccessible. Due to the legitimate appearance of the relayed traffic, pivoting is extremely difficult to detect. Although the consequences of these attacks are known to be severe, existing defenses suffer from drawbacks such as high processing delays, low accuracy, or reliance on network-wide participation, making them inconvenient or even ineffective. This work presents Stitch, a host-based system that uses the programmable kernel to detect pivoting in real time. By observing host-traversing flows, Stitch uses process tracing to effectively combine system and network-level information, connecting incoming and outgoing communications and identifying pivoting characteristics between them. Showing 31% gains in accuracy over state-of-the-art pivoting defenses and a maximum false positive rate of 0.006% over two separate real-world deployments, Stitch covers the gap in current pivot detection solutions by providing accurate, lightweight, and independent coverage for vulnerable hosts in a network.