返回
Attack scenario reconstruction approach using attack graph and alert data mining
DOI:10.1016/j.jisa.2020.102522.png)
摘要
En 中文
Existing alert correlation methods do not consider the unsuccessful paths and true negative alerts of IDS, which affects the completeness and visualization of attack restoring. To overcome this, an attack graph based alert correlation approach is proposed. The attack graph is first created using the toolkit MulVAL based on the network connectivity and known vulnerabilities, which gives the full view of all the vulnerabilities and their interdependence. Then, the alerts were mapped to attack graph to exhibit the intrusion situation initially. Afterwards, the attack sequences are output from the set of mapped alerts to reflect the initial attack paths. Afterwards, similar attack sequences are clustered together to obtain the preliminary attack scenarios. Finally, by analyzing the cohesive relationship between the subscenarios, the unreported true negative alerts are detected to improve the reconstruction by merging the broken attack scenarios. Experiments on the tested network and Defcon CTF23 dataset indicate that the proposed approach can restore attack scenarios more completely and further be used for attack forensics and traceability as well as for providing visualization support for comprehensive vulnerability analysis and targeted intrusion prevention. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Alert correlation
Attack scenario reconstruction
Attack graph
Attack sequences clustering
Data mining
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
IF:
3.7
论文数:
1.9K
被引数:
4.9K
机构
引用论文
A Framework for Cyber-Topology Attacks: Line-Switching and New Attack Scenarios网络拓扑攻击的框架: 线路切换和新的攻击场景
A review of attack graph and attack tree visual syntax in cyber security网络安全中的攻击图和攻击树视觉语法综述
COMPUTER SCIENCE REVIEW
IF12.7
没有更多内容

