Soteria: An Approach for Detecting Multi-Institution Attacks
Abstract
We present Soteria, a data processing pipeline for detecting multi-institution attacks. Multi-institution attacks contact large number of potential targets looking for vulnerabilities that span multiple institutions. Soteria uses a set of Machine Learning techniques to detect future attacks, predict their future targets, and ranks attacks based on their predicted severity. Our evaluation with real data from Canada wide institutions networks shows that Soteria can predict future attacks with 95% recall rate, predict the next targets of an attack with 97% recall rate, and can detect attacks in the first 20% of their life span. Soteria is deployed in production at CANARIE Canada wide network that connects tens of Canadian academic institutions.
Collections
Cite this version of the work
Saif Zabarah
(2023).
Soteria: An Approach for Detecting Multi-Institution Attacks. UWSpace.
http://hdl.handle.net/10012/19008
Other formats