• DocumentCode
    1574951
  • Title

    Building intrusion path graphs for security incident handling procedures

  • Author

    Liao, Guo-Tan ; Chen, Li-Ru ; Cheng, Bo-Chao ; Chen, Huan ; Hsu, Ping-Hai

  • Author_Institution
    Dept. of Commun. Eng., Nat. Chung-Cheng Univ., Chiayi, Taiwan
  • fYear
    2010
  • Firstpage
    267
  • Lastpage
    272
  • Abstract
    Hardening network services and network architecture is the best defense and the easiest way to reduce security risks. However, there is no effective solution to correlate all weaknesses, network topology with connectivity, and intrusion alerts. As a result, it can be difficult for network administrators to determine the root cause of a security incident. In this paper, we propose “GReat Evil ENcroachments Eradicator (GREENER)”, which can analyze the above network information in-depth and establish an intrusion path graph to display comprehensive information of security breaches. With the help of GREENER, system administrators can discover detailed information about an incident and rapidly remove network intrusion issues associated with the hardening process to prevent the same type of intrusion from happening again. This study has demonstrated that GREENER meets the requirements for mitigating security threats and provides a practical security incident response solution.
  • Keywords
    graph theory; security of data; hardening process; intrusion path graph; network architecture; network intrusion issues; network service; security incident; security risk; system administrator; Fires; Green products; Internet; Intrusion detection; Network topology; Operating systems;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Information Technologies (ISCIT), 2010 International Symposium on
  • Conference_Location
    Tokyo
  • Print_ISBN
    978-1-4244-7007-5
  • Electronic_ISBN
    978-1-4244-7009-9
  • Type

    conf

  • DOI
    10.1109/ISCIT.2010.5664848
  • Filename
    5664848