期刊文献+

基于多维告警融合的攻击目的预测系统

An Attack Plan Recognition System Based On Multi-alert Fusion
下载PDF
导出
摘要 本文论述了基于多维告警融合的攻击目的预测系统的设计与实现。该系统利用系统状态的可证实性以及其与IDS告警之间的因果关系,先通过贝叶斯网络对已有证据进行补足完善,再利用完善后的告警信息对攻击者的攻击目的进行目的预测,从而达到了提高预测准确率的目的。 This paper presents an attack plan recognition system which is based on multi-alert fusion. Based on the vindicability of system status and causality between System alert and IDS alert, this system calculate the confidence of each alert by using Bayesian networks, and then reason about attack plans with the high-reliable evidence we got.
出处 《微计算机信息》 北大核心 2008年第27期29-31,共3页 Control & Automation
基金 国家自然科学基金资助项目(NO.60702042)项目名称:网络视频信息传播控制技术研究
关键词 入侵检测 贝叶斯网络 目的预测 Intrusion Detection Bayesian Network plan recognition
  • 相关文献

参考文献6

  • 1Attack Plan Recognition and Prediction Using Causal Networks. ACSAC. 2004.
  • 2Javabayes. http://www -2. cs.cmu.edu/javabayes/Home/. Accessed on May 04, 2007.
  • 3Plan Recognition in Intrusion Detection Systems. IEEE. 2001
  • 4Reasoning about Complementary Intrusion Evidence. ACSAC. 2004.
  • 5邓琦皓,吕晓斌,罗军勇.基于入侵行为模式的告警关联[J].微计算机信息,2005,21(10X):8-10. 被引量:6
  • 6Hostile Plan Recognition and Opposition. International Conference on Machine Learning and Cybernetics.2005

二级参考文献2

  • 1A.Valdes and K.Skinner. probabilistic Alert Correlation [C]. In Fourth International Worshop on the Recent Advances in Itrusion Detection(RAID' 2001),Davis,USA,Oct 2001.
  • 2P.Ning, D.Reeves,and Yun Cui. Correlating Alerts Using Prerequisites of Intrusions. Technical Report TR-2001-13, North Carolina State University,Department of Computer Science, Dec 2001.

共引文献5

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部