article · International Journal of Safety and Security Engineering
Threat actors often move laterally through a corporate network to gain access to sensitive data from other machines once they have entered the environment.This is often achieved by using valid and privileged accounts to propagate within the network.However, detecting authentication attempts made by attackers can be challenging for security teams, as these attempts often resemble logons made by users and system administrators.The goal of our research is to develop an approach to identify malicious authentication events on Windows Active Directory environments using statistical analysis.We propose a feature extraction and hashing method applied to events generated by the Windows operating system following a successful logon and conduct statistical analysis to identify rare authentication characteristics that may indicate malicious activity.Our method was applied to a real corporate log with synthetic malicious events and demonstrated the ability to detect malicious authentication attempts effectively.We identified new authentication patterns, some of which were malicious.By using our proposed approach, security defenders can identify and prevent unauthorized access to sensitive data in their network environments.
This page summarises published work. The authoritative version sits with the publisher.
DOI: 10.18280/ijsse.130501
Is something wrong with this record? Report it or request removal.
Discussion
Have you built on this work, tried to replicate it, or seen it applied in practice? Share what you know. Verified researchers and MARATTO™ domain experts can open a discussion, and any member can reply. Contributions are reviewed before they appear.
No discussion yet. Open the first thread.
New to MARATTO™? Create a free account.