OAK

Event Log Analysis Framework based on the ATT&CK Matrix in Cloud Environment

Metadata Downloads
Alternative Title
클라우드 환경에서의 ATT&CK Matrix 기반 이벤트 로그 분석 프레임워크
Abstract
With the increasing trend of Cloud migration, security threats in the Cloud computing environment have also experienced a significant increase. Consequently, the importance of efficient incident investigation through log data analysis is being emphasized. In Cloud environments, the diversity of services and ease of resource creation generate a large volume of log data. This results in difficulties determining which events to investigate when an incident occurs, and examining all the extensive log data requires considerable time and effort. Therefore, a systematic approach for efficient data investigation is necessary.
CloudTrail, the Amazon Web Services(AWS) logging service, collects logs of all API call events occurring in an account. However, CloudTrail lacks insights on which logs to analyze in the event of an incident. This paper proposes an automated analysis framework that integrates Cloud Matrix and event information for efficient incident investigation, enabling simultaneous examination of user behavior log events frequency and attack information. This is expected to contribute to Cloud incident investigations by efficiently identifying critical events based on the ATT&CK Framework.
Author(s)
김예은
Issued Date
2024
Awarded Date
2024-02
Type
Dissertation
URI
https://repository.sungshin.ac.kr/handle/2025.oak/1458
http://dcollection.sungshin.ac.kr/common/orgView/000000014994
Alternative Author(s)
Kim yeeun
Affiliation
성신여자대학교 일반대학원
Department
일반대학원 미래융합기술공학과
Advisor
김성민
Table Of Contents
Ⅰ. Introduction 1
Ⅱ. Background 4
1. Security Threats in Cloud Environments 4
2. AWS CloudTrail 7
Ⅲ. Related Works 10
1. Cloud Log Analysis 10
Ⅳ. Cloud Event Log Analysis Framework 13
1. Event Classification System Module 16
1) Establish Cloud Log Collection Environment 16
2) Analysis Attack Time 19
3) Analysis eventName 21
4) Map the ATT&CK Matrix 23
2. Statistical Analysis of the eventName 25
3. Log Analysis Module 29
1) Collection/Extraction Log & Extraction Log Fields 29
2) Create Log Analysis DB 33
4. Event Log Analysis Framework 35
Ⅴ. Performance Evaluation 38
1. ATT&CK Tactics Coverage Test 38
1) Analysis of Discovery(TA0007) 39
2) Analysis of Persistence(TA0003) 41
3) Analysis of Credential Access(TA0006) 43
Ⅵ. Conclusion 47
Degree
Master
Publisher
성신여자대학교 일반대학원
Appears in Collections:
미래융합기술공학과 > 학위논문
공개 및 라이선스
  • 공개 구분공개
  • 엠바고2024-02-23
파일 목록

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.