Alert correlation by a retrospective method

  • Authors:
  • Ping Yi;Hongkai Xing;Yue Wu;Linchun Li

  • Affiliations:
  • Information Security National Engineering Laboratory, School of Information Security Engineering, Shanghai Jiao Tong University, Shanghai, China;Information Security National Engineering Laboratory, School of Information Security Engineering, Shanghai Jiao Tong University, Shanghai, China;Information Security National Engineering Laboratory, School of Information Security Engineering, Shanghai Jiao Tong University, Shanghai, China;Information Security National Engineering Laboratory, School of Information Security Engineering, Shanghai Jiao Tong University, Shanghai, China

  • Venue:
  • ICOIN'09 Proceedings of the 23rd international conference on Information Networking
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

IDS may result in many intrusion alerts. A general approach for solving this problem is to do some correlation analysis with these alerts and build attack scenario. Author presents a method for alert correlation through results tracing back to reasons. According to hacker attacks linked to a certain sequence characteristics, we correlate the alerts through results tracing back to reasons and gain the correlated alerts. This method can found internal relations of invasion, to accurately identify intrusion targets. Through succeed attacks to match the previous attacks, we can greatly reduce the volume of data, and improve speed and efficiency for correlation analysis.