클라우드 환경에서의 ATT&CK 매트릭스 기반 이벤트 로그 분석 프레임워크

Vol. 34, No. 2, pp. 263-279, 4월. 2024
10.13089/JKIISC.2024.34.2.263, Full Text:
Keywords: Cloud computing, AWS CloudTrail, eventName, ATT&CK Matrix
Abstract

With the increasing trend of Cloud migration, security threats in the Cloud computing environment have also experienced a significant increase. Consequently, the importance of efficient incident investigation through log data analysis is being emphasized. In Cloud environments, the diversity of services and ease of resource creation generate a large volume of log data. Difficulties remain in determining which events to investigate when an incident occurs, and examining all the extensive log data requires considerable time and effort. Therefore, a systematic approach for efficient data investigation is necessary. CloudTrail, the Amazon Web Services(AWS) logging service, collects logs of all API call events occurring in an account. However, CloudTrail lacks insights into which logs to analyze in the event of an incident. This paper proposes an automated analysis framework that integrates Cloud Matrix and event information for efficient incident investigation. The framework enables simultaneous examination of user behavior log events, event frequency, and attack information. We believe the proposed framework contributes to Cloud incident investigations by efficiently identifying critical events based on the ATT&CK Framework.

Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from December 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
김예은, 김정아, 채시윤, 홍지원, 김성민, "Event Log Analysis Framework Based on the ATT&CK Matrix in Cloud Environments," Journal of The Korea Institute of Information Security and Cryptology, vol. 34, no. 2, pp. 263-279, 2024. DOI: 10.13089/JKIISC.2024.34.2.263.

[ACM Style]
김예은, 김정아, 채시윤, 홍지원, and 김성민. 2024. Event Log Analysis Framework Based on the ATT&CK Matrix in Cloud Environments. Journal of The Korea Institute of Information Security and Cryptology, 34, 2, (2024), 263-279. DOI: 10.13089/JKIISC.2024.34.2.263.