摘要
论文提出一系列的技术来整合两种互补型的报警关联方法:基于报警属性之间的相似性(聚类关联),和基于攻击的因果关系(因果关联)。尤其是根据入侵报警间的因果关系和它们需要满足的等同约束关系来假设和推理可能被IDSs漏报的攻击,同时使用一定的方法来整理假设的攻击重建更简单更可信的攻击场景。
This paper presents some techniques to integrate two complementary types of alert correlation methods:those based on the similarity between alert attributes(clustering correlation),and those based on causal correlation of attacks (causal correlation).Especially,this paper presents techniques to hypothesize and reason about attacks possibly missed by IDSs based on the equality constrain and causual relation between intrusion alerts they must satisfy.At the same time, this page uses the certain method to consolidate the hypothesized attacks in order to rebuild more simple and creditable attack scenarios.
出处
《计算机工程与应用》
CSCD
北大核心
2006年第5期117-120,124,共5页
Computer Engineering and Applications
基金
国家自然科学基金重点资助项目(编号:90104030)
国家973基础研究发展规划资助项目(编号:G1999035801)
关键词
聚类关联
因果关联
假设攻击
等同约束
clustering correlation,causal correlation,hypothesize attack,equality constraint