Suppr超能文献

2024年Linux系统的高级持续性威胁(APT)与入侵检测评估数据集

Advanced Persistent Threat (APT) and intrusion detection evaluation dataset for linux systems 2024.

作者信息

Karim Syed Sohaib, Afzal Mehreen, Iqbal Waseem, Abri Dawood Al

机构信息

Department of Information Security, National University of Science and Technology (NUST), Islamabad-44000, Pakistan.

Electrical and Computer Engineering Department, College of Engineering, Sultan Qaboos University, Al-Khud, 123 Muscat, Oman.

出版信息

Data Brief. 2024 Mar 5;54:110290. doi: 10.1016/j.dib.2024.110290. eCollection 2024 Jun.

Abstract

The novel dataset called Linux-APT Dataset 2024 captures Advanced Persistent Threat (APT) attacks along with other latest and sophisticated payloads. Existing datasets lacks latest attacker's techniques and procedures, APTs tactics and configuration to capture maximum Linux log sources to observe the working and behaviour of an APT in a detailed manner. The environment which supported us in capturing the logs is composed of Linux machines and a centralized logging system configured appropriately to captures and detect all possible events and logs for an APT and other complex intrusion. Unlike Microsoft Windows, Linux logging system are investigated enough and usually systems relies on limited log sources but for an APT, all possible log sources should be evaluated and added to completely analyse the behaviour, trajectory, and operation of an APT. To keep the dataset up to date and realistic, recent payloads and APTs are emulated in the environment. A well-known cyber-security framework 'MITRE ATT&CK' is utilised to map the behaviour and operation in a generalized manner after capturing the events and logs. This dataset can be used for training and conducting a variety of experiments to build as well as design the solutions for detecting most recent intrusions and APT attacks for Linux System.

摘要

名为“Linux-APT数据集2024”的新型数据集捕捉了高级持续性威胁(APT)攻击以及其他最新、复杂的有效载荷。现有数据集缺乏最新攻击者的技术和程序、APT战术及配置,无法捕捉到最多的Linux日志源以详细观察APT的工作情况和行为。支持我们捕捉日志的环境由Linux机器和一个经过适当配置的集中式日志系统组成,该系统能够捕捉和检测APT及其他复杂入侵的所有可能事件和日志。与微软Windows不同,Linux日志系统的研究不够充分,而且通常系统依赖有限的日志源,但对于APT来说,应该评估并添加所有可能的日志源,以便全面分析APT的行为、轨迹和操作。为了使数据集保持最新和真实,在该环境中模拟了近期的有效载荷和APT。在捕捉事件和日志后,利用一个著名的网络安全框架“MITRE ATT&CK”以通用方式映射行为和操作。该数据集可用于训练和进行各种实验,以构建和设计用于检测Linux系统最新入侵和APT攻击的解决方案。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/c605/11220842/77b92f97fb62/gr1.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验