Soteria: An Approach for Detecting Multi-Institution Attacks
Loading...
Date
2023-01-02
Authors
Zabarah, Saif
Advisor
Boutaba, Raouf
Al-Kiswany, Samer
Al-Kiswany, Samer
Journal Title
Journal ISSN
Volume Title
Publisher
University of Waterloo
Abstract
We present Soteria, a data processing pipeline for detecting multi-institution attacks. Multi-institution attacks contact large number of potential targets looking for vulnerabilities that span multiple institutions. Soteria uses a set of Machine Learning techniques to detect future attacks, predict their future targets, and ranks attacks based on their predicted severity. Our evaluation with real data from Canada wide institutions networks shows that Soteria can predict future attacks with 95% recall rate, predict the next targets of an attack with 97% recall rate, and can detect attacks in the first 20% of their life span. Soteria is deployed in production at CANARIE Canada wide network that connects tens of Canadian academic institutions.
Description
Keywords
cybersecurity, systems