首页> 外文会议>International Conference on Networking, Architecture, and Storage >Discovering Novel Multistage Attack Patterns in Alert Streams
【24h】

Discovering Novel Multistage Attack Patterns in Alert Streams

机译:在警报流中发现新型多级攻击模式

获取原文
获取外文期刊封面目录资料

摘要

With the growing deployment of network security devices, the large volume of alerts gathered from these devices often overwhelm the administrator, and make it almost impossible to discover complicated multistage attacks in time. It is necessary to develop a real-time system to detect the ongoing attacks and predict the upcoming next step of a multistage attack in alert streams, using known attack patterns. So it is a key mission to make sure that the pattern definition is correct, complete and up to date. In this paper, a classical data mining algorithm is used to help us discover attack patterns, construct and maintain rules. It can overcome the highly dependent on knowledge of experts, time-consuming and error-prone drawbacks in previous approaches using manual analysis. Unfortunately, for a dynamic network environment where novel attack strategies appear continuously, the method shows a limited capability to detect the novel attack patterns. We can address the problem by presenting a novel approach using incremental mining algorithm to discover new attack patterns that appear recently. A series of experiments show the validity of the methods in this paper.
机译:随着网络安全设备的越来越多的部署,从这些设备收集的大量警报通常会压倒管理员,并使时间几乎无法及时发现复杂的多级攻击。有必要使用已知的攻击模式,开发一个实时系统来检测持续的攻击,并预测即将到来的临时攻击中的多级攻击的下一步。因此,确保模式定义是正确的,完成和最新的关键任务。在本文中,使用经典的数据挖掘算法来帮助我们发现攻击模式,构建和维护规则。它可以克服使用手动分析的先前方法中对专家的知识,耗时和误差缺陷的高度依赖性。遗憾的是,对于动态网络环境连续出现新颖的攻击策略,该方法显示了检测新的攻击模式的有限能力。我们可以通过呈现使用增量挖掘算法的新方法来解决问题,以发现最近出现的新攻击模式。一系列实验表明了本文中的方法的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号