摘要
使用因果关联方法构建攻击场景时,漏报警易引发关联图的分裂.针对此问题,提出了一种改进的基于因果关联的攻击场景重构方法.该方法根据报警相关度确定可组合的关联图,利用网络弱点和攻击关系推出漏报警,使得分裂的关联图能够组合起来,进而重建完整的攻击场景.实验结果表明了该方法的有效性.
Causal correlation method was one of the most representative methods for reconstructing attack scenario. However, the correlation graph would be split because of missing alerts in some condition. This paper proposes an improved attack scenario reconstructing method based on causal correlation. The method identifies the correlation graphs to be integrated through alert relativity, and reasons out missing alerts by analyzing network vulnerability and exploit. The experimental results show that the method is valid to combine the split correlation graphs and reconstruct attack scenario.
出处
《微电子学与计算机》
CSCD
北大核心
2009年第6期121-124,128,共5页
Microelectronics & Computer
基金
河南省重点科技攻关项目(082102210076)
关键词
因果关联
攻击场景重建
网络弱点
causal correlation
attack scenario reconstruction
network vulnerability