Event Log Analysis Framework based on the ATT&CK Matrix in Cloud Environment
- Alternative Title
- 클라우드 환경에서의 ATT&CK Matrix 기반 이벤트 로그 분석 프레임워크
- Abstract
- With the increasing trend of Cloud migration, security threats in the Cloud computing environment have also experienced a significant increase. Consequently, the importance of efficient incident investigation through log data analysis is being emphasized. In Cloud environments, the diversity of services and ease of resource creation generate a large volume of log data. This results in difficulties determining which events to investigate when an incident occurs, and examining all the extensive log data requires considerable time and effort. Therefore, a systematic approach for efficient data investigation is necessary.
CloudTrail, the Amazon Web Services(AWS) logging service, collects logs of all API call events occurring in an account. However, CloudTrail lacks insights on which logs to analyze in the event of an incident. This paper proposes an automated analysis framework that integrates Cloud Matrix and event information for efficient incident investigation, enabling simultaneous examination of user behavior log events frequency and attack information. This is expected to contribute to Cloud incident investigations by efficiently identifying critical events based on the ATT&CK Framework.
- Author(s)
- 김예은
- Issued Date
- 2024
- Awarded Date
- 2024-02
- Type
- Dissertation
- URI
- https://repository.sungshin.ac.kr/handle/2025.oak/1458
http://dcollection.sungshin.ac.kr/common/orgView/000000014994
- Alternative Author(s)
- Kim yeeun
- Affiliation
- 성신여자대학교 일반대학원
- Department
- 일반대학원 미래융합기술공학과
- Advisor
- 김성민
- Table Of Contents
- Ⅰ. Introduction 1
Ⅱ. Background 4
1. Security Threats in Cloud Environments 4
2. AWS CloudTrail 7
Ⅲ. Related Works 10
1. Cloud Log Analysis 10
Ⅳ. Cloud Event Log Analysis Framework 13
1. Event Classification System Module 16
1) Establish Cloud Log Collection Environment 16
2) Analysis Attack Time 19
3) Analysis eventName 21
4) Map the ATT&CK Matrix 23
2. Statistical Analysis of the eventName 25
3. Log Analysis Module 29
1) Collection/Extraction Log & Extraction Log Fields 29
2) Create Log Analysis DB 33
4. Event Log Analysis Framework 35
Ⅴ. Performance Evaluation 38
1. ATT&CK Tactics Coverage Test 38
1) Analysis of Discovery(TA0007) 39
2) Analysis of Persistence(TA0003) 41
3) Analysis of Credential Access(TA0006) 43
Ⅵ. Conclusion 47
- Degree
- Master
- Publisher
- 성신여자대학교 일반대학원
-
Appears in Collections:
- 미래융합기술공학과 > 학위논문
- 공개 및 라이선스
-
- 파일 목록
-
Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.