Detecting Structurally Anomalous Logins Within Enterprise Networks
Hossein Siadati, Nasir D. Memon
摘要
Many network intrusion detection systems use byte sequences to detect lateral movements that exploit remote vulnerabilities. Attackers bypass such detection by stealing valid credentials and using them to transmit from one computer to another without creating abnormal network traffic. We call this method Credential-based Lateral Movement. To detect this type of lateral movement, we develop the concept of a Network Login Structure that specifies normal logins within a given network. Our method models a network login structure by automatically extracting a collection of login patterns by using a variation of the market-basket analysis algorithm. We then employ an anomaly detection approach to detect malicious logins that are inconsistent with the enterprise network's login structure. Evaluations show that the proposed method is able to detect malicious logins in a real setting. In a simulated attack, our system was able to detect 82% of malicious logins, with a 0.3% false positive rate. We used a real dataset of millions of logins over the course of five months within a global financial company for evaluation of this work.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Hopper: Modeling and Detecting Lateral MovementGrant Ho, Mayank Dhiman, Devdatta Akhawe, Vern Paxson 等USENIX Security 2021 · 被引用 41 次
- KnowGraph: Knowledge-Enabled Anomaly Detection via Logical Reasoning on Graph DataAndy Zhou, Xiaojun Xu, Ramesh Raghunathan, Alok Lal 等CCS 2024 · 被引用 5 次
- ShadowMove: A Stealthy Lateral Movement StrategyAmirreza Niakanlahiji, Jinpeng Wei, Md Rabbi Alam, Qingyang Wang 等USENIX Security 2020
- Probabilistic Hash Embeddings for Online Learning of Categorical FeaturesAodong Li, Abishek Sankararaman, Balakrishnan NarayanaswamyAAAI 2026
它引用的顶会 Paper1
相关 Paper
- How to Cover up Anomalous Accesses to Electronic Health RecordsXiaojun Xu, Qingying Hao, Zhuolin Yang, Bo Li 等USENIX Security 2023
- Detecting Credential Spearphishing in Enterprise SettingsGrant Ho, Aashish Sharma, Mobin Javed, Vern Paxson 等USENIX Security 2017 · 被引用 94 次
- Detecting Stuffing of a User's Credentials at Her Own AccountsKe Coby Wang, Michael K. ReiterUSENIX Security 2020
- Euler: Detecting Network Lateral Movement via Scalable Temporal Graph Link PredictionIsaiah J. King, H. Howie HuangNDSS 2022
- Jbeil: Temporal Graph-Based Inductive Learning to Infer Lateral Movement in Evolving Enterprise NetworksJoseph Khoury, Dorde Klisura, Hadi Zanddizari, Gonzalo De La Torre Parra 等S&P 2024 · 被引用 28 次
