METHOD FOR IMPROVING SECURITY IN AN ELECTRONIC COMMUNICATIONS NETWORK
Patent Information
- Application Number
- DE502022003833
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-03-19
- Filing Date
- 2022-03-17
- Publication Date
- 2025-05-22
- Estimated Expiration
- 2042-03-17
AI Technical Summary
Existing methods for using deception technology in electronic communication networks lack a systematic approach for selecting and placing decoys and lures effectively, making it difficult to detect and localize cyber attacks.
The method involves determining an attack vector, creating an attack graph, selecting and distributing decoys and lures based on the attack graph's structure, and evaluating the change in attack paths to optimize the placement of decoys and lures.
This approach enhances the detection and localization of cyber attacks by making attack paths more recognizable and reliable, allowing for a measurable improvement in security through the optimized distribution of decoys and lures.
Description
[0001] The invention relates to a method for improving security in an electronic communication network using deception technology, in which lures and decoys are distributed in the communication network to detect an attacker in the communication network.
[0002] Such methods, which use so-called deception technology, are used to defend against and detect cyberattacks. The goal is to lure attackers into traps (decoys) using bait (also called lures or breadcrumbs). In this case, an attacker has already successfully penetrated a network, achieved persistence, and possibly already gained control of one or more devices. However, the attack could not be detected and localized using other methods. If the use of the lures or interaction with the decoys is detected, the attack can be detected and localized. One such method is known, for example, from the publication US 9,807,115 B2.
[0003] There are a multitude of possible decoys and lures, as well as ways of distributing them, limited only by the ingenuity of the defender and the characteristics of the communications network being defended. Decoys can represent services, server systems, or industrial control systems, for example. Lures can be, among other things, Active Directory objects (GPOs, SPNs, accounts), cookies, stored credentials, or certificates.
[0004] However, the current state of the art lacks a systematic approach to selecting the appropriate decoys and lures and where to place them. It is also important to be able to evaluate the changes resulting from the selection and placement of the decoys and lures. If the degree of improvement between the situation before and after deployment of a possible variant of decoys and lures can be measured with regard to the desired goal, a meaningful selection between the variants can be made.
[0005] Both - a systematic approach to selection and placement as well as the ability to evaluate - are crucial prerequisites for transforming the task into an optimization problem that can be addressed using mathematical approaches, machine learning algorithms or generative programming.
[0006] It is therefore the object of the invention to provide a system for the selection and placement of lures and decoys, by means of which the lures and decoys are distributed in the communication network in the most optimal manner possible in order to detect an attack as effectively as possible.
[0007] For this purpose, the invention proposes, based on a method of the type mentioned at the outset, that an attack vector on the communication network is determined, an attack graph is created based on the attack vector, which represents possible attack points and maps attack paths as an acyclic, i.e., cycle-free, directed graph with at least one sink representing the attack target and at least one source representing the attack point, the type and number of lures and decoys are determined based on the structure of the attack graph, and the lures and decoys are distributed in the communication network using an objective function, whereby the objective function takes the following specifications into account: a) shorter paths to the attack target or targets of the attack graph are particularly attractive to attackers, b) a decoy is placed on as many paths as possible to the attack target or targets of the attack graph, c) the lures and decoys are arranged as close as possible to the attack points of the attack graph,whereby a new attack graph is formed by the distribution of the lures and decoys, and the original attack graph is then compared with the newly formed attack graph and the change is evaluated.
[0008] In the method according to the invention, deception technology is used for the first time to optimally select and distribute lures and decoys based on a previously formed attack graph.
[0009] The attack graph is modeled as an acyclic, directed graph whose sinks are the target of the attacker.
[0010] The distribution of decoys and lures in the environment to be protected changes the original attack graph. An improvement for the defender is achieved when the possible paths in the new attack graph now lead earlier, faster, and more frequently via lures and decoys, thus making the attack detectable earlier and more reliably. The degree of improvement results from a comparison of the original attack graph and the attack graph modified by the deployment of lures and decoys. The resulting value of the objective function is a measure of the improvement and makes different solutions comparable and assessable.
[0011] A further development of the method according to the invention provides for at least two attack vectors to be defined, from which an attack graph is created, and the placement of the lures and decoys in the respective attack graphs is overlaid. This allows different types of attacks to be considered. At the same time, common structures are utilized in the placement and redundancy is avoided. This makes attack detection even more effective.
[0012] Additionally, it is advantageous to include the complexity of deploying lures and decoys as an additional specification in the objective function. The placement of lures and decoys within the network requires varying levels of technical complexity. Therefore, different placements also entail different costs. Cost optimization is therefore also considered in the objective function.
[0013] A particularly useful development of the invention provides for the use of machine learning methods in the implementation of the method. This measure allows for continuous and automated improvement of the distribution of lures and decoys. The use of machine learning methods using statistical methods is made possible by the inventive ability to evaluate the results.
[0014] The invention is explained in more detail below with reference to the drawings. They show: Figure 1: a schematic flow diagram of the method according to the invention in an embodiment; Figure 2: schematically an attack graph before deployment of the lures of the decoys; Figure 3: schematically the attack graph from Figure 2 after distribution of the decoys' lures in a first variant. Figure 4: schematically shows the attack graph from Figure 2 after distributing the lures of the decoys in a second variant.
[0015] In Figure 1 It is shown how the method according to the invention can be used to systematically determine, evaluate and optimize the type, number and placement of decoys and lures using mathematical methods based on the example of graph theory.
[0016] The attacker's path along their attack vector can be understood as a path along the edges (sometimes lures) and nodes (sometimes decoys) of a graph. The nature of the edges (network connections, pipes, permission relationships, etc.) and nodes (systems, services, etc.) results from the attack vector. These paths are modeled as attack graphs. While these attack graphs have been used to analyze and identify desirable configuration changes (see, for example, "P. Ammann, D. Wijesekera, and S. Kaushik, "Scalable, Graph-Based Network Vulnerability Analysis," ACSAC, 2002"), they have not yet been applied to the problem of selecting and placing decoys and lures, or to deception technology in general. Step 1: Determine the attack vector
[0017] In a first step of the inventive method, an attack vector is determined. An attacker's activities can be divided into the categories of reconnaissance, planning (plan), and action (act). The order is not important, and all phases can be repeated multiple times. The information obtained in the reconnaissance phases influences the type and chosen path of the attack – the so-called attack vector. The task of deception technology is to influence the information obtained in a way that matches the attack vector so that the chosen path leads via a decoy as early as possible or information from a lure is used, the use of which can be determined by other means. Step 2: Formation of the attack graph
[0018] In order to be able to detect and assess a change later, the second step of the inventive method creates attack graphs taking into account the attack vectors for the existing environment before deploying decoys and lures. This can be illustrated using the well-known "Identity Snowball" attacks (see, for example, "P. Ammann, D. Wijesekera and S. Kaushik, "Scalable, Graph-Based Network Vulnerability Analysis," ACSAC, 2002"). In this attack, an attacker gains greater privileges by gradually assuming new identities and exploiting them to compromise additional computers and identities. This attack technique has been an essential tool for human attackers (APTs) and automated malware attacks (Emotet / Trickbot) for many years.It is important to note that this attack technique is not based on exploiting programming errors that could be fixed with a patch, but rather utilizes fundamental mechanisms of systems such as Microsoft's Active Directory, Kerberos, or NTLM, and is difficult to detect using conventional means. This represents an important application area for deception technology. Starting with the attack vector, the existing environment can be represented in an attack graph, in which the nodes represent domains, user accounts, computers, groups, group policies, and organizational units, and the directed edges represent rights relationships and active sessions (AdminTo, TrustedBy, HasSession, GenericAll, AllExtendedRights, AllowedtoDelegate, Owns, GetChangesAll, etc.). Established tools exist for collecting, constructing, and storing such an attack graph (see, for example, R. Vazarkar, p.Heiniger and nikallass, "SharpHound3," [Online]. Available: https: / / github.com / BloodHoundAD / SharpHound3). Their high relevance is also reflected in their widespread use among attackers and security experts.
[0019] For the example of the "Identity Snowball" attack (see above), with the goal of gaining the highest privileges in the attacked structure, an acyclic, directed graph is first created from the acquired data, whose sinks are the group of "domain administrators." The sources of the graph represent possible attack points. The paths from the sources to the sinks represent the possible attack paths. Attackers use tools such as "BloodHound" (see A. Robbins, R. Vazarkar, and W. Schroeder, "BloodHound," [Online]. Available: https: / / github.com / BloodHoundAD / BloodHound) to create such acyclic, directed graphs and find optimal attack paths. Step 3: Selecting the lures and decoys
[0020] Just as the attack vector dictates the schema of the attack graph, the schema of the attack graph determines the selection of decoys and lures. Using the "Identity Snowball" attack vector as an example (see above), the decoys are computers, and the lures are user accounts, computers, groups, group policies, and organizational units configured to alter the structure of the attack graph. Other decoys and lures are not considered for this specific attack vector. 4th step: Formation of the parameters of the objective function
[0021] To find the optimal placement of decoys and lures, combinatorial optimization methods are applied, which select those with optimal objective function values from the set of possible distributions. In this example, the constraints considered include, among other things, upper limits on the number of decoys and lures relative to the size and complexity of the target environment to be protected.
[0022] These trees are modified by deploying decoys and lures. According to the invention, the goal is to guide the attacker's path over one of the deployed decoys and thus detect the attack. The objective function therefore considers the following specifications: Shorter paths are more attractive to the attacker. Each additional node increases the effort and the risk of detection. Not all edges (lures) have the same cost. The path over an edge can be weighted according to how technically easy it is for an attacker to follow and the associated risk of detection. The more attractive a path, the more important it is that it leads via a decoy or a detectable lure. As many paths as possible should lead via a decoy or a detectable lure (weighted according to the attractiveness of the paths). The earlier (i.e., the closer to an attack point) a decoy or a detectable lure is placed, the better.
[0023] Based on the objective function value, the individual attack graphs and their underlying distributions of decoys and lures can be evaluated and compared. An optimal solution is found using a suitable combinatorial optimization method known in principle to those skilled in the art.
[0024] In a further development of the invention, the design of the heuristics and the approximation algorithms for solving the optimization problem is supported or automated by the use of machine learning. Current research suggests that this is possible for recurring tasks with different but similarly structured data (see R. Ancarani, "Not All Paths are Created Equal, Attackers' Economy (Part 1)," 08 11 2019. [Online]. Available: https: / / riccardoancarani.github.io / 2019-11-08-not-all-paths-are-equal / ). Step 5: Overlay and result
[0025] Attack graphs can be used to model a multitude of possible attack vectors and thus serve as a basis for the optimized selection and distribution of decoys and lures. This allows the procedure described above to be applied to other conceivable attack vectors, finding an optimized partial solution for each. The partial solutions are then overlaid to form an overall solution.
[0026] The overall result found through the overlay is a multidimensionally optimized defense based on deception technology.
[0027] In Figure 2A simplified attack graph is shown and designated in its entirety by reference numeral 1. This was created as described above using the inventive method after the attack vector was determined. The attack graph is represented as an acyclic, directed graph, in which a sink 2, the group of domain administrators ("Domain Admin Group"), represents the target of the potential attacker 4. Sources 3 represent possible points of attack for the potential attacker. These are, for example, computers in the modeled network. The sink 2 can be reached from the sources 3 via nodes and edges (represented by directional arrows).
[0028] After creating the attack graph, the available decoys (dashed lines) and lures (dotted lines) are determined. The decoys and lures are distributed based on the objective function according to the invention and its specifications. Possible resulting attack graphs 1a, 1b are shown in Figure 3 and 4 shown. If an attacker 4 now penetrates the network via one of the sources 3 representing the possible attack points, the attack is detected if the attacker 4 encounters one of the deployed decoys and thus falls into the trap.
[0029] According to the invention, the resulting attack graph is evaluated based on the objective function.
[0030] For the attack graphs simplified here for clarity, edges have equal costs and detection occurs only on the decoys.
[0031] For example, the objective function is defined as follows: max A * N sd + B * N md + N rd − N p − E + M p − M d − M sl − M sd with N sd Number of paths with decoys that are shorter than the shortest path without decoys. AWeighting factor N md Number of paths with decoys that are shorter than the average path length and greater than or equal to the minimum path length of the paths without decoys. BWeighting factor N p Number of paths without decoys N d Number of paths with decoys N rd N p - N sd - N md (remaining paths with decoys) EAnum of possible attack points M p Average length of the paths without decoy M d Average length of the paths with decoy M sl Average distance of lures to attack points M sd Average distance of decoys to attack points
[0032] For the variants according to Figure 3 and Figure 4 This results in the following objective function values, with the weighting factors set to A = 10 and B = 2: Variant from Figure 3 : 10 * 3 + 2 * 0 + 1 − 5 − 5 + 9 − 6 , 75 − 2 , 75 − 4 , 00 = 16 , 50 Variant from Figure 4 : 10 * 1 + 2 * 0 + 1 − 5 − 5 + 9 − 9 , 75 − 4 , 25 − 7 , 75 = − 11 , 75
[0033] The evaluation therefore shows that the Figure 3The variant shown is more efficient because the attacker is detected on more paths - i.e. with a higher probability - and earlier because the decoys are placed closer to the sources 3 as possible attack points.
Claims
1. Method for improving the security of an electronic communication network using a deception technology, in which lures and decoys are distributed in the communication network, in order to detect an attacker in the communication network, characterised in that - an attack vector on the communication network is determined, - an attack graph (1) is drawn up, on the basis of the attack vector, which graph shows possible attack points and attack paths as acyclic directed graph having at least one sink (2) representing the target, and at least one source (3) representing the relevant attack point, - the type and the number of lures and decoys are determined on the basis of the structure of the attack graph (1), and - the lures and decoys are distributed in the communication network using a target function, wherein the target function takes into account the following parameters: a) shorter paths to the target or the targets of the attack graph (1) are particularly attractive for attackers (4), b) a decoy is placed on as many paths as possible to the target or the targets of the attack graph (1), c) the lures and decoys are arranged as close as possible to the attack points of the attack graph (1), wherein a new attack graph (1a, 1b) is created by the distribution of the lures and decoys, and wherein subsequently a comparison of the original attack graph (1) with the newly created attack graph (1a, 1b) is carried out, and the change is assessed on the basis of the target function value.
2. Method according to claim 1, characterised in that at least two attack vectors are specified, from which in each case one attack graph (1) is drawn up, and the positioning of the lures and decoys in the respective attack graphs (1) is overlaid.
3. Method according to either claim 1 or claim 2, characterised in that d) the complexity of the application of lures and decoys is used as a further parameter in the target function.
4. Method according to any of the preceding claims, characterised in that a plurality of iterations of the method according to claim 1 are passed through.
5. Method according to any of the preceding claims, characterised in that machine learning methods are used when carrying out the method.