期刊文献+

基于描述逻辑的告警信息关联

Alert Correlation Based on Description Logics
原文传递
导出
摘要 随着网络安全问题的日益突出,IDS被更多地用于安全防护,然而每天数以千计的告警信息却使得安全管理员无从招架。因此,自动关联有逻辑联系的告警信息从而减少告警数量已成为IDS日后发展的关键。论文以描述逻辑为基础,用它对攻击进行统一定义;以攻击场景为载体,用它来分析匹配相继出现的告警信息;以能力集为纽带,用它来串联起一幅幅攻击场景,从而能清晰地展现不同告警之间所隐含的逻辑关系,进而为实现关联归并提供依据。 As the problem of network security is getting worse, more and more IDSs have been used for networK protection However, so many security administrators are overwhelmed by thousands of alerts generated by IDSs everyday. Therefore, it has become a key development for IDS to automatically correlate these alerts and thus reduce their numbers. In this paper, a novel method is proposed, which is based on description logics and is used to define the attacks. This method takes attack scenarios as carriers to match the in-succession alerts and sets of abilities as bridges to construct attack scenarios. By this way, the inherent logic relations between different alerts can be displayed clearly and thus the basis for realization of the alert correlation and merge-sort is provided.
出处 《信息安全与通信保密》 2007年第9期125-128,共4页 Information Security and Communications Privacy
关键词 入侵检测系统 描述逻辑 攻击场景 能力 告警关联 intrusion detection system description logics attack scenario ability alert correlation
  • 相关文献

参考文献4

  • 1[1]Valdes A,Skinner K.Probabilistic Alert Correlation[A].In:Proceedings of the Workshop on Recent Advances in Intrusion Detection,2001:54~68.
  • 2[2]Debar H,Wespi A.Aggregation And Correlation of Intrusion Detection Alerts[J].In:Proceedings of the Fourth International Symposium,Recent Advances in Intrusion Detection,Davis,CA,USA,2001:85~103.
  • 3[3]Cuppens F,Mige A.Alert Correlation in A Cooperative Intrusion Detection Framework[A].In:Proc.of the 2002 IEEE Symposium on Security and Privacy,May 2002:202~215.
  • 4[4]Ning P,Cui Y,Reeves D S.Constructing Attack Scenarios Through Correlation of Intrusion Alerts[C].In:Proc.of the 9th ACM Conference on Computer and Communications Security,Washington,D.C.,November 2002:245~254.

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部