期刊文献+

考虑置信度的告警因果关联的研究 被引量:5

Research on Causal Correlation of Alerts with Confidence Measurement
原文传递
导出
摘要 一个成功的网络攻击往往由若干个处于不同阶段的入侵行为组成,较早发生的入侵行为为下一阶段的攻击做好准备。在因果关联方法中,可以利用入侵行为所需的攻击前提和造成的攻击结果,重构攻击者的攻击场景。论文引入了告警关联置信度的属性描述,用于分析因果关联结果的可信度,进而能够进一步消除虚假关联关系。通过DARPA标准数据集分析,该方法取得了较好的实验结果。 A successful network attack is usually composed of different attacks in different stages, with the early ones preparing for the later ones. In the method of causal correlating, intrusion alerts are correlated by using prerequisites and consequences of the corresponding attacks so as to reconstruct attack scenarios. In this paper, confidence measurement is introduced as an attribute of correlation between alerts, thus to analyze the reliability of causal correlation and reduce the false correlations. The desired results have been obtained in the experiment using the standard data set DARPA
作者 唐婵娜 范磊
出处 《信息安全与通信保密》 2009年第6期83-85,共3页 Information Security and Communications Privacy
基金 863资助(项目号:2007AA01Z473)
关键词 入侵检测 告警关联 因果关联 置信度 intrusion detection alert correlation causal correlation confidence measurement
  • 相关文献

参考文献3

  • 1Ning Peng,Cui Yun,Reeves S.Douglas.Constructing Attack Scenarios through Correlation of Intrusion Alerts[C].In Proceedings of the 9th ACM Conference on Computer and Communications Security.Washingtong,D.C.,2002:245 -254.
  • 2Valdes Alfonso,Skinner Keith.Probabilistic Alert Correlation[C].In Proceedings of Recent Advances in Intrusion Detection,4th International Symposium,Lecture Notes in Computer Science.Heidelberg:Springer-Verlag.2001:54-68.
  • 3Zhu Bin,Ghorbani A All.Alert Correlation for Extracting Attack Strategies[J].International Journal of Network security,2006,03(03) 224-258.

同被引文献16

引证文献5

二级引证文献8

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部