Constructing attack scenarios through correlation of intrusion alerts
Proceedings of the 9th ACM conference on Computer and communications security
Alert Correlation in a Cooperative Intrusion Detection Framework
SP '02 Proceedings of the 2002 IEEE Symposium on Security and Privacy
Techniques and tools for analyzing intrusion alerts
ACM Transactions on Information and System Security (TISSEC)
Hi-index | 0.00 |
With the increasing amount of security audit data, management and analysis of it become a critical and challenging issue. Security alerts and threat analysis project (SATA) aims at analysing security events and detecting security threat. In this paper, we proposed a novel method of constructing attack scenarios in order to recognise multi-stage attack behaviours and predict next potential attack steps of the attacker. Our method based on statistical method using the feature of time consecution association between contextual attack steps. Besides, we proposed a new method of computing the correlativity between two contextual alerts which enhances the correlation-ship of the attack steps constructing attack scenario models and ensures the accuracy of the final correlation result. The idea is easy to implement and can be used to detect novel multi-stage attacks. Experiment shows that our method is effective and feasible.