首页> 外文会议>IEE Colloquium on Design and Development of Autonomous Agents, 1995 >A structural framework for modeling multi-stage network attacks
【24h】

A structural framework for modeling multi-stage network attacks

机译:用于建模多阶段网络攻击的结构框架

获取原文

摘要

Incidents such as Solar Sunrise and Nimda demonstrate the need to expressively model distributed and complex network attacks. To protect information systems, system administrators must be able to represent vulnerabilities in a way that lends itself to correlation, analysis, and prediction. State of the art intrusion detection and attack analysis systems struggle to effectively represent sophisticated attacks. Strategic models express exploits as goal-oriented attack trees. Attack trees represent adversarial behavior by connecting events in 'AND'-'OR' tree structures. However these structures need to be enhanced and expressed in a formal manner in order to adequately represent the complexity of recent cyber attacks. This paper provides a methodology for capturing the structure of various network vulnerabilities and multi-stage attacks. By extending the attack tree paradigm, we provide a context sensitive attack modeling framework that, through abstraction, supports incident correlation, analysis, and prediction.
机译:诸如Solar Sunrise和Nimda之类的事件表明,需要对分布式和复杂的网络攻击进行富有表现力的建模。为了保护信息系统,系统管理员必须能够以有助于进行关联,分析和预测的方式来表示漏洞。最新的入侵检测和攻击分析系统难以有效地代表复杂的攻击。战略模型将漏洞利用表示为面向目标的攻击树。攻击树通过连接“与”-“或”树结构中的事件来表示对抗行为。但是,这些结构需要以正式的方式加以增强和表达,以充分代表最近的网络攻击的复杂性。本文提供了一种捕获各种网络漏洞和多阶段攻击的结构的方法。通过扩展攻击树范例,我们提供了一个上下文敏感的攻击建模框架,该框架通过抽象支持事件关联,分析和预测。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号