Example: bachelor of science

The Diamond Model of Intrusion Analysis - Active Response

Approved for public release; distribution is Diamond Model of Intrusion AnalysisSergio Intelligence analysts should be self-conscious about their reasoningprocess. They should think about how they make judgments and reachconclusions, not just about the judgments and conclusions themselves."Richards J. Heuer Jr.[1] Intrusion Analysis is as much about tcpdump as astronomy is abouttelescopes"Chris Sanders[2]AbstractThis paper presents a novel Model of Intrusion Analysis built by analysts, derivedfrom years of experience, asking the simple question, What is the underlying methodto our work? The Model establishes the basic atomic element of any Intrusion activity,the event, composed of four core features: adversary, infrastructure, capability, and vic-tim.

has occurred with the potential and preferred attack vectors enabling more effective analy-sis and mitigation strategy development. This ultimately allows a more efficient allocation of defense resources. Additionally, prior work in [21] has already shown the applicability of attack graphs directly in intrusion detection systems.

Tags:

  Enabling

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of The Diamond Model of Intrusion Analysis - Active Response

1 Approved for public release; distribution is Diamond Model of Intrusion AnalysisSergio Intelligence analysts should be self-conscious about their reasoningprocess. They should think about how they make judgments and reachconclusions, not just about the judgments and conclusions themselves."Richards J. Heuer Jr.[1] Intrusion Analysis is as much about tcpdump as astronomy is abouttelescopes"Chris Sanders[2]AbstractThis paper presents a novel Model of Intrusion Analysis built by analysts, derivedfrom years of experience, asking the simple question, What is the underlying methodto our work? The Model establishes the basic atomic element of any Intrusion activity,the event, composed of four core features: adversary, infrastructure, capability, and vic-tim.

2 These features are edge-connected representing their underlying relationships andarranged in the shape of a Diamond , giving the Model its name: the Diamond further defines additional meta-features to support higher-level constructs such aslinking events together into activity threads and further coalescing events and threadsinto activity groups. These elements, the event, thread, and group all contribute to afoundational and comprehensive Model of Intrusion activity built around analytic pro-cesses. It captures the essential concepts of Intrusion Analysis and adversary operationswhile allowing the Model flexibility to expand and encompass new ideas and Model establishes, for the first time, a formal method applying scientific principlesto Intrusion Analysis particularly those of measurement, testability, and repeatability providing a comprehensive method of activity documentation, synthesis, and cor-relation.

3 This scientific approach and simplicity produces improvements in analyticeffectiveness, efficiency, and accuracy. Ultimately, the Model provides opportunities tointegrate intelligence in real-time for network defense, automating correlation acrossevents, classifying events with confidence into adversary campaigns, and forecastingadversary operations while planning and gaming mitigation Introduction52 Related Work63 Diamond Model Overview74 Diamond Adversary .. Capability .. Command and Control (C2) .. Infrastructure .. Victim .. Vulnerabilities and Exposures.

4 Event Meta-Features .. Timestamp .. Phase .. Result .. Direction .. Methodology .. Resources .. Meta-Feature Expansions .. 185 Extended Diamond Social-Political .. Persistent Adversary Relationships .. Cyber-Victimology .. Shared Threat Space .. Technology .. 246 Contextual Indicators257 Analytic Centered Approaches .. Victim-Centered Approach .. Capability-Centered Approach .. Infrastructure-Centered Approach .. Adversary-Centered Approach .. Social-Political-Centered Approach .. Technology-Centered Approach.

5 308 Activity Adversary Process .. Analytic Hypothesis Support .. Activity-Attack Graph .. 399 Activity Step 1: Analytic Problem .. Step 2: Feature Selection .. Step 3: Creation .. Activity Group Creation Example .. Step 4: Growth .. Step 5: Analysis .. Step 6: Redefinition .. Activity Group Families .. 4910 Planning and Gaming5111 Future Work5412 Conclusion553 List of Figures1 A Diamond Event .. 92 An Extended Diamond Event .. 193 Adversary-Victim Relationships .. 214 Degree of Persistence Spectrum .. 225 Analytic Pivoting Example Using the Diamond .

6 276 Diamond Activity Thread Example .. 317 Diamond Adversary Process Example .. 378 Activity-Attack Graph Example .. 399 Activity Group Creation .. 4710 Activity Group Growth .. 4811 Diamond Model /Kill Chain Course of Action Matrix Example .. 5341 IntroductionThe discipline of Intrusion Analysis has existed since the discovery of the first hackers and malicious insiders, mostly slyly, infiltrate and attack while intrusionanalysts and system administrators work to uncover, understand, and thwart their oper-ations. The questions remain little-changed since the discipline s epoch: the who, what,when, where, why, and how.

7 Historically, these questions informed incident Response toaddress the activity at-hand but defenders lacked the models and frameworks for activitydocumentation, synthesis, and correlation necessary to answer a question of growing im-portance: will the adversary return as part of a coordinated campaign? Yet the questionultimately leads organizations away from tactical mitigation (countering the activity) andtowards strategic mitigation (countering the adversary) thereby increasing the effectivenessof mitigation and the adversary s cost to conduct paper presents a novel Model of Intrusion Analysis built by analysts, derived from yearsof experience, asking the simple question, What is the underlying method of our work?

8 Itarrives at its name, the Diamond Model , for its simple organization of the most fundamentalaspects of malicious activity into the shape of a Diamond . Our Model establishes, for thefirst time, a formal method applying scientific principles to Intrusion Analysis : those ofmeasurement, testability, and repeatability providing a simple, formal, and comprehensivemethod of activity documentation, synthesis, and correlation. This scientific approach andsimplicity produces improvements in analytic effectiveness, efficiency, and Model is at once simple and complex, informal and formal, useful for Analysis of bothinsider and external threats.

9 Informally, analysts easily comprehend the Model makingit useful in the heat of pursuit on a daily basis. The Model is the basis of an ontology2and presents a framework upon which to discover new activity, maximize analytic pivotopportunities, correlate and synthesize new information, and pursue the adversary overtime, all while improving communication and , the Model is a mathematical framework allowing the application of game, graph,and classification/clustering theory to improve Analysis and decision making. The formalityprovides several benefits: testable analytic hypotheses ensuring repeatability and accuracyof analytic results, easier hypothesis generation, automated correlation across events, quicklyclassifying events with confidence into adversary campaigns, and forecasting adversary op-erations while planning and gaming mitigation strategies.

10 Ultimately, this formality leadsto the Model s ability to integrate correlated intelligence for network defense capabilities,easily evolving to adopt new adversary infrastructure, capabilities, and importantly, the Model is purposefully generic and thereby expandable and accurately captures the essential concepts of Intrusion Analysis and adversary this paper the term Intrusion is used to denote all malicious and nefarious activity targetingcomputer systems and Model does not present a new ontology, taxonomy, sharing format, or protocol but by its funda-mental nature should form the basis of these.


Related search queries