【24h】

ATTACK SCENARIO DETECTION BASED ON EXPERT SYSTEM

机译:基于专家系统的攻击场景检测

获取原文

摘要

Traditional intrusion detection systems only focus on low-level attacks, and only generate isolated alerts.But in practice an attack is made up of a sequence of logical scenarios.As a result, it is difficult for human to understand alerts and take appropriate actions.This paper presents a practical technique to address this issue.The paper proposes a rule-based hierarchical model to construct attack scenarios, and use expert system (CLIPS) as the engine to detect scenarios.In this paper a concrete design method is discussed and applied to analyze snort alerts, the proposed approach can delect attack scenarios in real time, the rules only describe the properties of attacks in a high level and avoid to describe the concrete network or host information, this guarantee the generality of this method, we adopt the known general expert system as the detection engine, so the implementation become very easy.
机译:传统的入侵检测系统只专注于低级攻击,只生成隔离的警报,但实际上攻击是由一系列逻辑场景组成的,因此人们很难理解警报并采取适当的措施。本文提出了一种解决该问题的实用技术。本文提出了一种基于规则的层次模型来构造攻击场景,并以专家系统(CLIPS)作为检测场景的引擎。本文讨论并应用了一种具体的设计方法。为了分析Snort警报,所提出的方法可以实时检测攻击情况,规则仅在较高的层次上描述了攻击的属性,避免描述具体的网络或主机信息,这保证了该方法的通用性,我们采用作为检测引擎已知的通用专家系统,因此实现变得非常容易。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号