A Bayesian network‐based approach for learning attack strategies from intrusion alerts. Issue 5 (30th May 2013)
- Record Type:
- Journal Article
- Title:
- A Bayesian network‐based approach for learning attack strategies from intrusion alerts. Issue 5 (30th May 2013)
- Main Title:
- A Bayesian network‐based approach for learning attack strategies from intrusion alerts
- Authors:
- Kavousi, Fatemeh
Akbari, Behzad - Abstract:
- <abstract abstract-type="main"> <title>ABSTRACT</title> <p>A tremendous number of low‐level alerts reported by information security systems clearly reflect the need for an advanced alert correlation system to reduce alert redundancy, correlate security alerts, detect attack strategies, and take appropriate actions against upcoming attacks. Up to now, a variety of alert correlation methods have been suggested. However, most of them rely on a priori and hard‐coded domain expert knowledge that leads to their difficult implementation and limited capabilities of detecting new attack strategies. To overcome the drawbacks of these approaches, the recent trend of research in alert correlation has gone towards extracting attack strategies through automatic analysis of intrusion alerts. In line with the recent researches, in this paper, we present new algorithms to automatically mine attack behavior patterns from historical alerts as accurately and efficiently as possible. Our system is composed of two main components. The first offline component automatically generates correlation rules by analyzing the previously observed alerts using a Bayesian causality analysis mechanism. Then, in the online alert correlation component, alerts are correlated using a hierarchical scheme and based on the extracted rules. Our experimental results clearly show efficiency of the proposed method in learning new attack strategies. Copyright © 2013 John Wiley & Sons, Ltd.</p> </abstract>
- Is Part Of:
- Security and communication networks. Volume 7:Issue 5(2014:May)
- Journal:
- Security and communication networks
- Issue:
- Volume 7:Issue 5(2014:May)
- Issue Display:
- Volume 7, Issue 5 (2014)
- Year:
- 2014
- Volume:
- 7
- Issue:
- 5
- Issue Sort Value:
- 2014-0007-0005-0000
- Page Start:
- 833
- Page End:
- 853
- Publication Date:
- 2013-05-30
- Subjects:
- Computer networks -- Security measures -- Periodicals
Computer security -- Periodicals
Cryptography -- Periodicals
005.805 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1939-0122 ↗
https://www.hindawi.com/journals/scn/ ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/sec.786 ↗
- Languages:
- English
- ISSNs:
- 1939-0114
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library HMNTS - ELD Digital store
- Ingest File:
- 3097.xml