节点文献

通过关联报警重建攻击场景

Rebuilding Attack Scenarios through Correlating Alerts

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 廖晓勇戴英侠

【Author】 Liao Xiaoyong Dai Yingxia (State Key Laboratory of Information Security,Graduate School,Chinese Academy of Sciences, Beijing 100039)

【机构】 中国科学院研究生院信息安全国家重点实验室中国科学院研究生院信息安全国家重点实验室 北京100039北京100039

【摘要】 论文提出一系列的技术来整合两种互补型的报警关联方法:基于报警属性之间的相似性(聚类关联),和基于攻击的因果关系(因果关联)。尤其是根据入侵报警间的因果关系和它们需要满足的等同约束关系来假设和推理可能被IDSs漏报的攻击,同时使用一定的方法来整理假设的攻击重建更简单更可信的攻击场景。

【Abstract】 This paper presents some techniques to integrate two complementary types of alert correlation methods:those based on the similarity between alert attributes(clustering correlation),and those based on causal correlation of attacks (causal correlation).Especially,this paper presents techniques to hypothesize and reason about attacks possibly missed by IDSs based on the equality constrain and causual relation between intrusion alerts they must satisfy.At the same time, this page uses the certain method to consolidate the hypothesized attacks in order to rebuild more simple and creditable attack scenarios.

【基金】 国家自然科学基金重点资助项目(编号:90104030);国家973基础研究发展规划资助项目(编号:G1999035801)
  • 【文献出处】 计算机工程与应用 ,Computer Engineering and Applications , 编辑部邮箱 ,2006年05期
  • 【分类号】TP393.08
  • 【被引频次】1
  • 【下载频次】128
节点文献中: 

本文链接的文献网络图示:

本文的引文网络