Title: Anonymized User-Computer Authentication Associations in Time

Los Alamos National Lab. (LANL), Los Alamos, NM (United States)
USDOE National Nuclear Security Administration (NNSA), Office of Defense Programs (DP) (NA-10)
Related Information: A. Hagberg, A. Kent, N. Lemons, and J. Neil. "Connected Components and Credential Hopping in Authentication Graphs" to be published by the IEEE in the Proceedings of the 2014 International Conference on Signal-Image Technology & Internet-Based Systems.
97 MATHEMATICS AND COMPUTING; Computer authentication; cybersecurity
  2. This data set represents 58 consecutive days of de-identified event data collected from five sources within Los Alamos National Laboratory’s corporate, internal computer network. The data sources include Windows-based authentication events from both individual computers and centralized Active Directory domain controller servers; process start andmore » stop events from individual Windows computers; Domain Name Service (DNS) lookups as collected on internal DNS servers; network flow data as collected on at several key router locations; and a set of well-defined red teaming events that present bad behavior within the 58 days. In total, the data set is approximately 12 gigabytes compressed across the five data elements and presents 1,648,275,307 events in total for 12,425 users, 17,684 computers, and 62,974 processes. Specific users that are well known system related (SYSTEM, Local Service) were not de-identified though any well-known administrators account were still de-identified. In the network flow data, well-known ports (e.g. 80, 443, etc) were not de-identified. All other users, computers, process, ports, times, and other details were de-identified as a unified set across all the data elements (e.g. U1 is the same U1 in all of the data). The specific timeframe used is not disclosed for security purposes. In addition, no data that allows association outside of LANL’s network is included. All data starts with a time epoch of 1 using a time resolution of 1 second. In the authentication data, failed authentication events are only included for users that had a successful authentication event somewhere within the data set. « less
