Publication | Closed Access
Correlating cyber incident information to establish situational awareness in Critical Infrastructures
13
Citations
14
References
2016
Year
Unknown Venue
EngineeringCritical Infrastructure ProtectionInformation SecuritySafety ScienceInformation ForensicsCommunicationCritical InfrastructureCyber MonitoringModern Attack CampaignsSystems EngineeringThreat (Computer)Situational AwarenessThreat DetectionIncident InformationInfrastructure SecurityComputer ScienceSecurity Information CorrelationThreat HuntingAdvanced Persistent ThreatsCyber Threat IntelligenceCybersecurity SystemCritical Infrastructures
Protecting Critical Infrastructures (CIs) against contemporary cyber attacks has become a crucial as well as complex task. Modern attack campaigns, such as Advanced Persistent Threats (APTs), leverage weaknesses in the organization's business processes and exploit vulnerabilities of several systems to hit their target. Although their life-cycle can last for months, these campaigns typically go undetected until they achieve their goal. They usually aim at performing data exfiltration, cause service disruptions and can also undermine the safety of humans. Novel detection techniques and incident handling approaches are therefore required, to effectively protect CI's networks and timely react to this type of threats. Correlating large amounts of data, collected from a multitude of relevant sources, is necessary and sometimes required by national authorities to establish cyber situational awareness, and allow to promptly adopt suitable countermeasures in case of an attack. In this paper we propose three novel methods for security information correlation designed to discover relevant insights and support the establishment of cyber situational awareness.
| Year | Citations | |
|---|---|---|
Page 1
Page 1