english Icono del idioma   español Icono del idioma  

Por favor, use este identificador para citar o enlazar este ítem: https://hdl.handle.net/20.500.12008/29279 Cómo citar
Título: A Process Mining-based approach for Attacker Profiling
Autor: Rodríguez, Marcelo
Betarte, Gustavo
Calegari, Daniel
Tipo: Preprint
Palabras clave: Cybersecurity, Process mining, Behaviour, Malware
Fecha de publicación: 2021
Resumen: Reacting adequately to cybersecurity attacks requires observing the attackers’ knowledge, skills, and behaviors to examine their influence over the system and understand the characteristics associated with these attacks. Profiling an attacker allows generating security countermeasures that can be adopted even from the design of the systems. For automated attackers, e.g. malware, it is possible to identify some structured behavior, i.e. a process-like behavior consisting of several (partial) ordered activities. Process Mining (PM) is a discipline from the organizational context that focuses on analyzing the event logs associated with executing the system’s processes to discover many aspects of process behavior. Few proposals are applying PM to attacker profiling. In this work, we explore the use of PM techniques to identify the behavior of cyber attackers. In particular, we illustrate, using an application example, how they can be adapted to an environment dominated by automated attackers. We discuss preliminary results and provide guidelines for future work.
Descripción: IEEE URUCON 2021, Montevideo, Uruguay. 24-26 November, 2021.
Editorial: IEEE
Citación: Rodríguez, M., Betarte, G. y Calegari, D. A Process Mining-based approach for Attacker Profiling [Preprint]. Publicado en : IEEE URUCON 2021, Montevideo, Uruguay. 24-26 November, 2021.
Licencia: Licencia Creative Commons Atribución - No Comercial - Sin Derivadas (CC - By-NC-ND 4.0)
Aparece en las colecciones: Reportes Técnicos - Instituto de Computación

Ficheros en este ítem:
Fichero Descripción Tamaño Formato   
RBC21.pdfPreprint327,38 kBAdobe PDFVisualizar/Abrir


Este ítem está sujeto a una licencia Creative Commons Licencia Creative Commons Creative Commons