摘要
由于协同攻击的复杂性 ,使传统检测方法难以对其进行有效地检测。在对协同攻击行为的层次性和关联性的分析基础上 ,使用条件关联方法对协同攻击进行检测。提出了一种适于进行关联分析的攻击表达方式和攻击动作链条的搜索方法。实验结果表明该方法可有效的将协同攻击链分离出来。
The complexity of coordinated attacks is difficult to detect efficiently by using the traditional methods such as misuse detection and anomaly detection.The coordinated attack is composed of many attack behaviors,among which there are some kinds of association.Based on the research work on the hierarchy and reciprocity of attack behaviors,this paper provides a solution for detecting coordinated attack with the conditional association method.A kind of attack representation that is suitable to association analysis has been introduced and the results of experiments have proved the feasibility of this method.
出处
《武汉理工大学学报》
CAS
CSCD
2004年第6期78-81,共4页
Journal of Wuhan University of Technology
关键词
入侵检测
协同攻击
关联分析
intrusion detection
coordinated attack
association analysis