کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456219 695675 2008 9 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Building network attack graph for alert causal correlation
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Building network attack graph for alert causal correlation
چکیده انگلیسی

Most network administrators have got unpleasant experience of being overwhelmed by tremendous unstructured network security alerts produced by heterogeneous devices. To date, various approaches have been proposed to correlate security alerts, including the adoption of attack graphs to clarify their causal relationship. However, there still lacks an efficient and operational method to generate attack graphs tailored to alert causal correlation.In this paper, we propose a kind of “one-step worst” attack graph which can be built in polynomial time using an intuitive object-oriented method. Based on the graph, a principle is given out to correlate security alerts into scenarios. To prove its feasibility, we implemented a prototype system which can efficiently divide real-time alert streams into plausible attack scenarios.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 27, Issues 5–6, October 2008, Pages 188–196
نویسندگان
, , , ,