• DocumentCode
    2386943
  • Title

    Generating Attack Scenarios with Causal Relationship

  • Author

    Cheng, Yu-Chin ; Chen, Chien-Hung ; Chiang, Chung-Chih ; Wang, Jun-Wei ; Laih, Chi-Sung

  • Author_Institution
    Nat. Cheng Kung Univ., Tainan
  • fYear
    2007
  • fDate
    2-4 Nov. 2007
  • Firstpage
    368
  • Lastpage
    368
  • Abstract
    With the incoming of information era, Internet has been developed rapidly and offered more and more services. However, intrusions, viruses and worms follow with the grown of Internet, spread widely all over the world within high speed network. Although many kinds of intrusion detection systems (IDSs) are developed, they have some disadvantages in that they focus on low-level attacks or anomalies, and raise alerts independently. In this paper, we give a formal description about attack patterns, attack transition states and attack scenarios. We proposed the system architecture to generate an attack scenario database correctly and completely. We first classify and extract attack patterns, then, correlate attack patterns with pre/post conditions matching and. Moreover, the approach, attack scenario generation with casual relationship (ASGCR), is proposed to build an attack scenario database Finally, we present the combination of our attack scenario database with security operation center (SOC) to implement the related components concerning alert integrations and correlations. It is shown that our method is better than CAML [4] since we can generate more attack scenarios effectively and correctly to help system managers to maintain network security.
  • Keywords
    Internet; computer viruses; database management systems; software architecture; Internet; attack scenario database; attack scenario generation with casual relationship; formal description; high speed network; information era; intrusion detection systems; low-level attacks; security operation center; system architecture; viruses; worms; Communication system security; Data security; Databases; High-speed networks; IP networks; Intrusion detection; National security; Sensor phenomena and characterization; Viruses (medical); Web and internet services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Granular Computing, 2007. GRC 2007. IEEE International Conference on
  • Conference_Location
    Fremont, CA
  • Print_ISBN
    978-0-7695-3032-1
  • Type

    conf

  • DOI
    10.1109/GrC.2007.117
  • Filename
    4403126