@inbook{33533c1963c34fdaad4a7eae16a43c80,
title = "Inferring the stealthy bridges between enterprise network islands in cloud using cross-layer bayesian networks",
abstract = "Enterprise networks are migrating to the public cloud to acquire computing resources for promising benefits in terms of efficiency, expense, and flexibility. Except for some public services, the enterprise network islands in cloud are expected to be absolutely isolated from each other. However, some “stealthy bridges” may be created to break such isolation due to two features of the public cloud: virtual machine image sharing and virtual machine co-residency. This paper proposes to use cross-layer Bayesian networks to infer the stealthy bridges existing between enterprise network islands. Prior to constructing cross-layer Bayesian networks, cloud-level attack graphs are built to capture the potential attacks enabled by stealthy bridges and reveal hidden possible attack paths. The result of the experiment justifies the crosslayer Bayesian network{\textquoteright}s capability of inferring the existence of stealthy bridges given supporting evidence from other intrusion steps in a multistep attack.",
author = "Xiaoyan Sun and Jun Dai and Anoop Singhal and Peng Liu",
note = "Funding Information: This work was supported by ARO W911NF-09-1-0525 (MURI), NSF CNS-1223710, NSF CNS-1422594, ARO W911NF-13-1-0421 (MURI), and AFOSR W911NF1210055. Publisher Copyright: {\textcopyright} Institute for Computer Sciences, Social Informatics and Telecommunications Engineering 2015.",
year = "2015",
doi = "10.1007/978-3-319-23829-6_1",
language = "English (US)",
series = "Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST",
publisher = "Springer Verlag",
pages = "3--23",
booktitle = "Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST",
address = "Germany",
}