TY - GEN
T1 - Asset risk scoring in enterprise network with mutually reinforced reputation propagation
AU - Hu, Xin
AU - Wang, Ting
AU - Stoecklin, Marc Ph
AU - Schales, Douglas L.
AU - Jang, Jiyong
AU - Sailer, Reiner
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2014/11/13
Y1 - 2014/11/13
N2 - Cyber security attacks are becoming ever more frequent and sophisticated. Enterprises often deploy several security protection mechanisms, such as anti-virus software, intrusion detection prevention systems, and firewalls, to protect their critical assets against emerging threats. Unfortunately, these protection systems are typically 'noisy', e.g., regularly generating thousands of alerts every day. Plagued by false positives and irrelevant events, it is often neither practical nor cost-effective to analyze and respond to every single alert. The main challenge faced by enterprises is to extract important information from the plethora of alerts and to infer potential risks to their critical assets. A better understanding of risks will facilitate effective resource allocation and prioritization of further investigation. In this paper, we present MUSE, a system that analyzes a large number of alerts and derives risk scores by correlating diverse entities in an enterprise network. Instead of considering a risk as an isolated and static property, MUSE models the dynamics of a risk based on the mutual reinforcement principle. We evaluate MUSE with real-world network traces and alerts from a large enterprise network, and demonstrate its efficacy in risk assessment and flexibility in incorporating a wide variety of data sets.
AB - Cyber security attacks are becoming ever more frequent and sophisticated. Enterprises often deploy several security protection mechanisms, such as anti-virus software, intrusion detection prevention systems, and firewalls, to protect their critical assets against emerging threats. Unfortunately, these protection systems are typically 'noisy', e.g., regularly generating thousands of alerts every day. Plagued by false positives and irrelevant events, it is often neither practical nor cost-effective to analyze and respond to every single alert. The main challenge faced by enterprises is to extract important information from the plethora of alerts and to infer potential risks to their critical assets. A better understanding of risks will facilitate effective resource allocation and prioritization of further investigation. In this paper, we present MUSE, a system that analyzes a large number of alerts and derives risk scores by correlating diverse entities in an enterprise network. Instead of considering a risk as an isolated and static property, MUSE models the dynamics of a risk based on the mutual reinforcement principle. We evaluate MUSE with real-world network traces and alerts from a large enterprise network, and demonstrate its efficacy in risk assessment and flexibility in incorporating a wide variety of data sets.
UR - http://www.scopus.com/inward/record.url?scp=84939535470&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84939535470&partnerID=8YFLogxK
U2 - 10.1109/SPW.2014.18
DO - 10.1109/SPW.2014.18
M3 - Conference contribution
AN - SCOPUS:84939535470
T3 - Proceedings - IEEE Symposium on Security and Privacy
SP - 61
EP - 64
BT - Proceedings - 2014 IEEE Security and Privacy Workshops, SPW 2014
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2014 IEEE Computer Society's Security and Privacy Workshops, SPW 2014
Y2 - 17 May 2014 through 18 May 2014
ER -