Continuously evolving cyber-attacks against industrial networks reduce the effectiveness of signature-based detection methods. Once malware has infiltrated a network (for example, entering via an unsecured device), it can infect further network nodes and carry out malicious activity. Infected nodes can exhibit unusual behaviour in their use of Address Resolution Protocol (ARP) calls within the network. In order to detect such anomalous nodes, we propose a two-stage method: (i) modelling of ARP call behaviour via hierarchical time series prediction methods, and (ii) exploiting Extreme Value Theory (EVT) to robustly detect whether deviations from expected behaviour are anomalous. EVT is able to handle heavy-tailed distributions which are exhibited by internet traffic. Empirical evaluations on a real-life dataset containing over 10M ARP calls from 362 nodes show that the proposed method results in considerably reduced number of false positives, addressing the problem of alert fatigue commonly reported by security professionals.
翻译:持续演变的工业网络网络攻击降低了基于签名的检测方法的有效性。一旦恶意软件侵入网络(例如通过不安全设备进入),便可能感染后续网络节点并实施恶意活动。受感染节点在使用地址解析协议(ARP)调用时可能表现出异常行为。为检测此类异常节点,我们提出一种两阶段方法:(i) 通过层次化时间序列预测方法对ARP调用行为进行建模,(ii) 利用极值理论(EVT)鲁棒地检测预期行为的偏差是否属于异常。EVT能够处理网络流量中常见的重尾分布。基于包含362个节点超过1000万次ARP调用的真实数据集的实证评估表明,所提方法显著减少了误报数量,有效解决了安全专业人员普遍报告的警报疲劳问题。