首页 | 本学科首页   官方微博 | 高级检索  
     

基于可信报警事件的在线攻击场景重构算法
引用本文:郭山清,曾英佩,谢立.基于可信报警事件的在线攻击场景重构算法[J].计算机科学,2006,33(8):100-105.
作者姓名:郭山清  曾英佩  谢立
作者单位:1. 南京大学计算机软件新技术国家重点实验室,南京210093
2. 南京大学计算机科学与技术系,南京210093
基金项目:江苏省自然科学基金;江苏省软件与集成电路专项基金
摘    要:传统的入侵检测系统仅提供大量独立的、原始的攻击报警信息,不利于用户和入侵响应系统对攻击及时做出响应,迫切需要根据低层的报警信息,建立高层的攻击场景,提高安全管理员对当前发生的攻击的认知度。本文利用贝叶斯规则首先对多个安全设备产生的报警信息进行过滤,生成了可信的报警事件集,在此基础上完成攻击场景的重构工作,减少了安全设备产生的误报信息对关联算法的影响,提高了关联算法的健壮性和可扩展性。描述的关联方法可以使报警事件的聚合操作和攻击场景重构同时进行,实现了对报警事件的在线分析功能,弥补了现有算法的不足。试验结果表明,该算法在场景重构和报警事件约减两个方面都表现出了良好的性能。

关 键 词:入侵检测  攻击场景  关联  贝叶斯规则  事件约减  在线分析

An Online Attack Scenarios Construction Algorithms Based on Delievable Alarms
GUO Shan-Qing,ZENG Ying-Pei,XIE-Li.An Online Attack Scenarios Construction Algorithms Based on Delievable Alarms[J].Computer Science,2006,33(8):100-105.
Authors:GUO Shan-Qing  ZENG Ying-Pei  XIE-Li
Affiliation:State Key Laboratory for Novel Software Technology, Nanjing University, Nanjing 210093; Department of Computer Science and Technology, Nanjing University, Nanjing 210093
Abstract:Traditional intrusion detection systems(IDSs) only provide large amount of independent, low-level attack alerts, though there may be logical connections between them. As a result, it is difficult for users or response systems to understand the alerts and take appropriate actions for these attacks. So it needs to deduce high-level attack scenarios and analysis the attack's objective from low-level attack alerts. This paper uses Bayesian rule to filter the alarm set,produces the believable alarm set and shows the most plausible ones among these possible scenarios based on this set,which decrease the effect of false negative alarm and improve this correlation algorithm's robustness and expansibility. This algorithm can also be used to analysis the online alarm set, which avoid the shortcomings of the existed algorithms. We evaluate this model with DARPA evaluation database, which shows good performance in attack scenario construction and alarm reduction.
Keywords:Intrusion detection  Attack scenario  Correlation  Alarm reduction  Online analysis
本文献已被 CNKI 维普 万方数据 等数据库收录!
点击此处可从《计算机科学》浏览原始摘要信息
点击此处可从《计算机科学》下载全文
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号