DocumentCode
2604376
Title
Using vulnerability information and attack graphs for intrusion detection
Author
Roschke, Sebastian ; Cheng, Feng ; Meinel, Christoph
Author_Institution
Hasso-Plattner-Inst. (HPI), Univ. of Potsdam, Potsdam, Germany
fYear
2010
fDate
23-25 Aug. 2010
Firstpage
68
Lastpage
73
Abstract
Intrusion Detection Systems (IDS) have been used widely to detect malicious behavior in network communication and hosts. IDS management is an important capability for distributed IDS solutions, which makes it possible to integrate and handle different types of sensors or collect and synthesize alerts generated from multiple hosts located in the distributed environment. Sophisticated attacks are difficult to detect and make it necessary to integrate multiple data sources for detection and correlation. Attack graph (AG) is used as an effective method to model, analyze, and evaluate the security of complicated computer systems or networks. The attack graph workflow consists of three parts: information gathering, attack graph construction, and visualization. This paper proposes the integration of the AG workflow with an IDS management system to improve alert and correlation quality. The vulnerability and system information is used to prioritize and tag the incoming IDS alerts. The AG is used during the correlation process to filter and optimize correlation results. A prototype is implemented using automatic vulnerability extraction and AG creation based on unified data models.
Keywords
data visualisation; graph theory; security of data; IDS management system; attack graph construction; attack graph visualization; attack graph workflow; correlation process; information gathering; intrusion detection systems; malicious behavior detection; vulnerability information; Correlation; Data mining; Data models; Databases; Security; Sensors; Software;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security (IAS), 2010 Sixth International Conference on
Conference_Location
Atlanta, GA
Print_ISBN
978-1-4244-7407-3
Type
conf
DOI
10.1109/ISIAS.2010.5604041
Filename
5604041
Link To Document