基于迭代预警关联的网络入侵场景提取方法

R. Anbarestani, B. Akbari, F. Fathi
{"title":"基于迭代预警关联的网络入侵场景提取方法","authors":"R. Anbarestani, B. Akbari, F. Fathi","doi":"10.1109/IRANIANCEE.2012.6292441","DOIUrl":null,"url":null,"abstract":"Alert correlation aims to provide an abstract and high-level view of environment security state, as one can extract attack strategies from raw intrusion alerts. Most existing alert correlation approaches depend on either expert knowledge or predefined patterns for detecting complex attack steps. In this paper we provide a Bayesian network based alert correlation approach that is able to discover attack strategies without need to expert knowledge. The main goal of this work is extracting attack scenarios, with taking into account the sequence of actions. We also try to eliminate redundant relationships in a detected attack scenario. The experimental evaluation using the well-known DARPA 2000 data set shows the efficiency of our proposed approach in extracting the intrusion scenarios.","PeriodicalId":308726,"journal":{"name":"20th Iranian Conference on Electrical Engineering (ICEE2012)","volume":"14 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-05-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"13","resultStr":"{\"title\":\"An iterative alert correlation method for extracting network intrusion scenarios\",\"authors\":\"R. Anbarestani, B. Akbari, F. Fathi\",\"doi\":\"10.1109/IRANIANCEE.2012.6292441\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Alert correlation aims to provide an abstract and high-level view of environment security state, as one can extract attack strategies from raw intrusion alerts. Most existing alert correlation approaches depend on either expert knowledge or predefined patterns for detecting complex attack steps. In this paper we provide a Bayesian network based alert correlation approach that is able to discover attack strategies without need to expert knowledge. The main goal of this work is extracting attack scenarios, with taking into account the sequence of actions. We also try to eliminate redundant relationships in a detected attack scenario. The experimental evaluation using the well-known DARPA 2000 data set shows the efficiency of our proposed approach in extracting the intrusion scenarios.\",\"PeriodicalId\":308726,\"journal\":{\"name\":\"20th Iranian Conference on Electrical Engineering (ICEE2012)\",\"volume\":\"14 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2012-05-15\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"13\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"20th Iranian Conference on Electrical Engineering (ICEE2012)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IRANIANCEE.2012.6292441\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"20th Iranian Conference on Electrical Engineering (ICEE2012)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IRANIANCEE.2012.6292441","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 13

摘要

警报关联旨在提供环境安全状态的抽象和高级视图,因为可以从原始入侵警报中提取攻击策略。大多数现有的警报关联方法要么依赖于专家知识,要么依赖于预定义模式来检测复杂的攻击步骤。本文提出了一种基于贝叶斯网络的警报关联方法,该方法能够在不需要专家知识的情况下发现攻击策略。这项工作的主要目标是提取攻击场景,并考虑到行动的顺序。我们还尝试在检测到的攻击场景中消除冗余关系。使用著名的DARPA 2000数据集进行的实验评估表明,我们提出的方法在提取入侵场景方面是有效的。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
An iterative alert correlation method for extracting network intrusion scenarios
Alert correlation aims to provide an abstract and high-level view of environment security state, as one can extract attack strategies from raw intrusion alerts. Most existing alert correlation approaches depend on either expert knowledge or predefined patterns for detecting complex attack steps. In this paper we provide a Bayesian network based alert correlation approach that is able to discover attack strategies without need to expert knowledge. The main goal of this work is extracting attack scenarios, with taking into account the sequence of actions. We also try to eliminate redundant relationships in a detected attack scenario. The experimental evaluation using the well-known DARPA 2000 data set shows the efficiency of our proposed approach in extracting the intrusion scenarios.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Geometrical analysis of altitude estimation error caused by pixel quantization in stereo vision Time-domain MoM for the scattering analysis of thin-wire structures within a ground using band-limited Second-Order Lagrange temporal basis functions Variable-structure position control-a class of fast and robust controllers for synchronous reluctance motor drives Analysis of corona effect on lightning performance of HV overhead transmission line using ATP/EMTP Font recognition using Variogram fractal dimension
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1