首页> 外文会议>Advanced International Conference on Telecommunications >Discovering Attack Strategies Using Process Mining
【24h】

Discovering Attack Strategies Using Process Mining

机译:使用Process Mining发现攻击策略

获取原文
获取外文期刊封面目录资料

摘要

Intrusion Detection Systems generate alerts which depend on manual analysis of a specialist to determine a response plan. However, these systems usually trigger thousands of alerts per day. Investigating unmanageable amounts of alerts manually becomes burdensome and error-prone. Besides, it complicates the analysis of critical alerts. In this paper, an approach is proposed to facilitate the investigation of huge amounts of intrusion detection alerts by a specialist. The proposed approach makes use of process mining techniques to discover attack strategies observed in intrusion alerts, which are presented to the network administrator in friendly visual models. Tests were performed using a real dataset from the University of Maryland. The results show that the proposed approach combines visual features along with quantitative measures that help the network administrator to analyze the alerts in an easy and intuitive manner.
机译:入侵检测系统产生警报,依赖于对专家的手动分析来确定响应计划。 然而,这些系统通常每天触发数千次警报。 调查手动变为繁重和容易出错的未管理量的警报。 此外,它使关键警报的分析复杂化。 在本文中,提出了一种方法,促进专家对大量入侵检测警报进行调查。 所提出的方法利用流程挖掘技术来发现入侵警报中观察到的攻击策略,这些技术在友好的视觉模型中向网络管理员呈现给网络管理员。 使用来自马里兰大学的真实数据集进行测试。 结果表明,该方法的方法结合了视觉功能以及有助于网络管理员以简单且直观的方式分析警报的定量措施。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号