首页> 外文会议>2012 9th International ISC Conference on Information Security and Cryptology. >Real-time attack scenario detection via intrusion detection alert correlation
【24h】

Real-time attack scenario detection via intrusion detection alert correlation

机译:通过入侵检测警报关联进行实时攻击场景检测

获取原文
获取原文并翻译 | 示例

摘要

Alert correlation systems attempt to discover the relations among alerts produced by one or more intrusion detection systems to determine the attack scenarios and their main motivations. The main purpose of this paper is to propose a new IDS alert correlation method to detect attack scenarios in real-time. The proposed method is based on causal approach due to the strength of causal methods in practice. Most of causal methods can be deployed offline but not in real-time due to time and memory limitations. In the proposed method the knowledge base of attack patterns is represented in a graph model called Causal Relations Graph. In offline, we construct some trees related to alerts probable correlations. In real-time for each received alert, we can find its correlations with previously received alerts by performing a search only in the corresponding tree. Thus processing time of each alert decreases significantly. In addition, the proposed method is immune to the deliberately slowed attacks. To verify the proposed method, it was implemented in C++ and we used DARPA2000 dataset to test it. Experimental results show the correctness of the proposed alert correlation and its efficiency with respect to the run time.
机译:警报关联系统试图发现一个或多个入侵检测系统产生的警报之间的关系,以确定攻击场景及其主要动机。本文的主要目的是提出一种新的IDS警报关联方法,以实时检测攻击场景。由于因果方法在实践中的优势,因此该方法基于因果方法。由于时间和内存的限制,大多数因果方法可以离线部署,但不能实时部署。在提出的方法中,攻击模式的知识库以称为因果关系图的图模型表示。在离线状态下,我们构建一些与警报可能的相关性相关的树。对于每个收到的警报,我们可以通过仅在相应树中执行搜索来实时找到其与先前收到的警报的相关性。因此,每个警报的处理时间显着减少。另外,所提出的方法不受故意减慢的攻击的影响。为了验证所提出的方法,该方法在C ++中实现,我们使用DARPA2000数据集对其进行了测试。实验结果表明,所提出的警报关联的正确性及其相对于运行时间的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号