Abstract | ||
---|---|---|
Detecting anomalies in login activities is a critical step in response to credential-based lateral movement attacks. Although attackers with compromised credentials can impersonate legal users and move laterally between computers without triggering the alarm, his login activities would likely deviate from the users' normal patterns. We propose AGE, an Authentication Graph Embedding based anomalous login activities detection system. The goal of authentication graph embedding is to capture comprehensive relationships that facilitate the construction of user profiles. Specifically, the user profiles contain three types of features: the familiarity-related features, the similarity-related features, and the lateral movement walks-related features. To evaluate AGE thoroughly, we use our synthetic malicious lateral movement traces as well as red team activities provided by CMU-CERT. Extensive experiments show that AGE achieves good performance and outperforms the baseline methods. Moreover, we also design experiments that will help us understand the authentication graph embedding. |
Year | DOI | Venue |
---|---|---|
2019 | 10.1007/978-3-030-41579-2_20 | INFORMATION AND COMMUNICATIONS SECURITY (ICICS 2019) |
Keywords | DocType | Volume |
Anomalous login activities detection, Authentication graph embedding, Lateral movement, User profiling | Conference | 11999 |
ISSN | Citations | PageRank |
0302-9743 | 0 | 0.34 |
References | Authors | |
0 | 4 |
Name | Order | Citations | PageRank |
---|---|---|---|
Renzheng Wei | 1 | 0 | 1.01 |
Li-jun Cai | 2 | 37 | 13.57 |
Aimin Yu | 3 | 4 | 4.80 |
Dan Meng | 4 | 37 | 16.11 |