【24h】

Knowledge-Based Model to Represent Security Information and Reason About Multi-stage Attacks

机译:基于知识的表示安全信息和多阶段攻击原因的模型

获取原文

摘要

In an intrusion detection context, none of the main detection approaches (signature-based and anomaly-based) are fully satisfactory. False positives and false negatives are the major limitations of such systems. The generated alerts are elementary and in huge numbers. Hence, alert correlation techniques are used to provide a complementary analysis to link elementary alerts and provide a more global intrusion view. It has been widely recognised that real cyber attacks consist of phases that are temporally ordered and logically connected. In this paper we present an improved knowledge-based causal alert correlation model. The correlation process is essentially modularized based on an extension of the properties and characteristics of the 'requires/provides ' model. The description of the knowledge base modeling is introduced consisting of attacks classes, vulnerabilities, and alerts generated by security tools. The proposed system is evaluated to detect simulated and real multi-stage attacks and it showes efficient capability to correlate the attacker behavior.
机译:在入侵检测环境中,没有一种主要的检测方法(基于签名和基于异常)是完全令人满意的。误报和误报是此类系统的主要限制。生成的警报是基本警报,数量巨大。因此,警报关联技术用于提供补充分析以链接基本警报并提供更全面的入侵视图。众所周知,真正的网络攻击由时间顺序和逻辑连接的阶段组成。在本文中,我们提出了一种改进的基于知识的因果警报关联模型。相关过程实质上是基于“需求/提供”模型的属性和特征的扩展而模块化的。介绍了知识库建模的描述,其中包括攻击类,漏洞和由安全工具生成的警报。对提出的系统进行了评估,以检测模拟的和实际的多阶段攻击,并且该系统显示了与攻击者行为相关的有效能力。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号