首页> 外文会议>International Conference on Information Assurance and Security >Automatic generation of correlation rules to detect complex attack scenarios
【24h】

Automatic generation of correlation rules to detect complex attack scenarios

机译:自动生成相关规则以检测复杂的攻击情形

获取原文

摘要

In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.
机译:在大型分布式信息系统中,警报关联系统对于处理大量的基本安全警报并在低级别事件和警报流中标识复杂的多步攻击非常必要。在本文中,我们显示出,一旦人类专家提供了从攻击树派生的行动树,那么全自动的转换过程就可以生成详尽的关联规则,而这些规则将是繁琐的,并且容易被手工枚举。转换依赖于对实际执行环境(系统拓扑,已部署服务等)各个方面的详细描述。因此,所生成的相关规则与所监视的信息系统的特性紧密相关。拟议的转换过程已在原型中实现,该原型生成以攻击描述语言表达的关联规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号