arrow
返回

Attack scenario reconstruction approach using attack graph and alert data mining

delete2020-10-01
delete25
PRE
AI
H
Hao Hu *
J
Jing Liu
Y
Yuchen Zhang
Y
Yuling Liu
X
Xiaoyu Xu
J
Jinglei Tan
DOI:10.1016/j.jisa.2020.102522delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Existing alert correlation methods do not consider the unsuccessful paths and true negative alerts of IDS, which affects the completeness and visualization of attack restoring. To overcome this, an attack graph based alert correlation approach is proposed. The attack graph is first created using the toolkit MulVAL based on the network connectivity and known vulnerabilities, which gives the full view of all the vulnerabilities and their interdependence. Then, the alerts were mapped to attack graph to exhibit the intrusion situation initially. Afterwards, the attack sequences are output from the set of mapped alerts to reflect the initial attack paths. Afterwards, similar attack sequences are clustered together to obtain the preliminary attack scenarios. Finally, by analyzing the cohesive relationship between the subscenarios, the unreported true negative alerts are detected to improve the reconstruction by merging the broken attack scenarios. Experiments on the tested network and Defcon CTF23 dataset indicate that the proposed approach can restore attack scenarios more completely and further be used for attack forensics and traceability as well as for providing visualization support for comprehensive vulnerability analysis and targeted intrusion prevention. (C) 2020 Elsevier Ltd. All rights reserved.
Keyword:
Alert correlation
Attack scenario reconstruction
Attack graph
Attack sequences clustering
Data mining
AI总结

AI总结

对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
1.9K
被引数:
4.9K

机构

P
pla information engineering university
学者数:
2.8K
论文数: 1.6K
被引数: 2
C
chinese academy of sciences
学者数:
56.7W
论文数: 45.0W
被引数: 704
引用论文

引用论文

An Intrusion Action-Based IDS Alert Correlation Analysis and Prediction Framework
err2019-01-01
err22
errOAAI
errZhang, Kai; Zhao, Fei; Luo, Shoushan; Xin, Yang; Zhu, Hongliang
err分享
err收藏
err分享
err收藏
Forest recovery and river discharge at the regional scale of Guangdong Province, China
err2010-09-01
err0
PREAI
errGuoyi Zhou; Xiaohua Wei; Yan Luo; Mingfang Zhang; Yuelin Li; Yuna Qiao; Haigui Liu; Chunlin Wang
err分享
err收藏
Taxonomy and Survey of Collaborative Intrusion Detection
err2015-05-11
err232
PREAI
errVasilomanolakis, Emmanouil; Karuppayah, Shankar; Muehlhaeuser, Max; Fischer, Mathias
err分享
err收藏
err分享
err收藏
Survey of Attack Projection, Prediction, and Forecasting in Cyber Security
err2019-01-01
err188
errOAAI
errHusak, Martin; Komarkova, Jana; Bou-Harb, Elias; Celeda, Pavel
err分享
err收藏
没有更多内容