论文部分内容阅读
Building attack scenario is one of the most important aspects in network security.This paper pro-posed a system which collects intrusion alerts,clusters them as sub-attacks using alerts abstraction,ag-gregates the similar sub-attacks,and then correlates and generates correlation graphs.The scenarios wererepresented by alert classes instead of alerts themselves so as to reduce the required rules and have the a-bility of detecting new variations of attacks.The proposed system is capable of passing some of the missedattacks.To evaluate system effectiveness,it was tested with different datasets which contain multi-stepattacks.Compressed and easily understandable Correlation graphs which reflect attack scenarios were gen-erated.The proposed system can correlate related alerts,uncover the attack strategies,and detect newvariations of attacks.
Building attack scenario is one of the most important aspects in network security.This paper pro-posed a system which collects intrusion alerts, clusters them as sub-attacks using alerts abstraction, ag-gregates the similar sub-attacks, and then correlates and generates correlation graphs.The profiles wererepresented by alert classes instead of alerts self so as to reduce the required rules and have the a-bility of detecting new variations of attacks.The proposed system is capable of passing some of the missed attacks.To evaluate system effectiveness, it was tested with different datasets which contain multi-stepattacks.Compacted and easily understandable Correlation maps which reflect attack plans were gen-erated.The proposed system can correlate related alerts, uncover the attack strategies, and detect newvariations of attacks.