A novel technique of recognising multi-stage attack behaviour. (3rd January 2011)
- Record Type:
- Journal Article
- Title:
- A novel technique of recognising multi-stage attack behaviour. (3rd January 2011)
- Main Title:
- A novel technique of recognising multi-stage attack behaviour
- Authors:
- Wang, Li
Li, Yao
Li, Zhi-tang - Abstract:
- With the increasing amount of security audit data, management and analysis of it become a critical and challenging issue. Security alerts and threat analysis project (SATA) aims at analysing security events and detecting security threat. In this paper, we proposed a novel method of constructing attack scenarios in order to recognise multi-stage attack behaviours and predict next potential attack steps of the attacker. Our method based on statistical method using the feature of time consecution association between contextual attack steps. Besides, we proposed a new method of computing the correlativity between two contextual alerts which enhances the correlation-ship of the attack steps constructing attack scenario models and ensures the accuracy of the final correlation result. The idea is easy to implement and can be used to detect novel multi-stage attacks. Experiment shows that our method is effective and feasible.
- Is Part Of:
- International journal of high performance computing and networking. Volume 6:Number 3/4(2010)
- Journal:
- International journal of high performance computing and networking
- Issue:
- Volume 6:Number 3/4(2010)
- Issue Display:
- Volume 6, Issue 3/4 (2010)
- Year:
- 2010
- Volume:
- 6
- Issue:
- 3/4
- Issue Sort Value:
- 2010-0006-NaN-0000
- Page Start:
- 174
- Page End:
- 180
- Publication Date:
- 2011-01-03
- Subjects:
- multi-stage attacks -- attack plan recognition -- security alerts -- correlativity -- threat analysis -- security threats -- intrusion detection
High performance computing -- Periodicals
Computer networks -- Periodicals
High performance computing
Periodicals
004.05 - Journal URLs:
- http://www.inderscience.com/jhome.php?jcode=ijhpcn ↗
http://www.metapress.com/openurl.asp?genre=journal&issn=1740-0562 ↗
http://www.inderscience.com/ ↗ - Languages:
- English
- ISSNs:
- 1740-0562
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 8682.xml