Algebra for capability based attack correlation

  • Authors:
  • Navneet Kumar Pandey;S. K. Gupta;Shaveta Leekha

  • Affiliations:
  • Indian Institute of Technology Delhi, Delhi, India;Indian Institute of Technology Delhi, Delhi, India;Indian Institute of Technology Delhi, Delhi, India

  • Venue:
  • WISTP'08 Proceedings of the 2nd IFIP WG 11.2 international conference on Information security theory and practices: smart devices, convergence and next generation networks
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Most of the existing intrusion detection systems (IDS) oftengenerate large numbers of alerts which contain numerous false positivesand non relevant positives. Alert correlation techniques aim to aggregateand combine the outputs of single/multiple IDS to provide a conciseand broad view of the security state of network. Capability based alertcorrelator uses notion of capability to correlate IDS alerts where capabilityis the abstract view of attack extracted from IDS alerts/alert. Tomake correlation process semantically correct and systematic, there is astrong need to identify the algebraic and set properties of capability. Inthis work, we identify the potential algebraic properties of capability interms of operations, relations and inferences. These properties give betterinsight to understand the logical association between capabilities whichwill be helpful in making the system modular. This paper also presentsvariant of correlation algorithm by using these algebraic properties. Tomake these operations more realistic, existing capability model has beenempowered by adding time-based notion which helps to avoid temporalambiguity between capability instances. The comparison between basicmodel and proposed model is exhibited by demonstrating cases in whichfalse positives have been removed that occurred due to temporal ambiguity.