论文部分内容阅读
在分析基于攻击前提和后果关联方法的基础上,提出了一种基于系统漏洞和报警相关度的攻击场景构建方法。它不仅能够利用系统漏洞信息验证报警的可靠性,排除误报,而且能够通过报警之间的相关度关联多跳攻击过程。实验结果表明,此方法能够有效地减少误报和漏报,从而有助于构建更加真实完整的攻击场景。
Based on the analysis of the methods based on attack prerequisite and consequence correlation, this paper proposes a method for constructing attack scenarios based on system loopholes and alarm correlation. It can not only use the system vulnerability information to verify the reliability of the alarm, eliminate false positives, but also can correlate the multi-hop attack process through the correlation between the alarms. Experimental results show that this method can effectively reduce false positives and false negatives, which helps to build a more realistic and complete attack scenarios.