DocumentCode
2386943
Title
Generating Attack Scenarios with Causal Relationship
Author
Cheng, Yu-Chin ; Chen, Chien-Hung ; Chiang, Chung-Chih ; Wang, Jun-Wei ; Laih, Chi-Sung
Author_Institution
Nat. Cheng Kung Univ., Tainan
fYear
2007
fDate
2-4 Nov. 2007
Firstpage
368
Lastpage
368
Abstract
With the incoming of information era, Internet has been developed rapidly and offered more and more services. However, intrusions, viruses and worms follow with the grown of Internet, spread widely all over the world within high speed network. Although many kinds of intrusion detection systems (IDSs) are developed, they have some disadvantages in that they focus on low-level attacks or anomalies, and raise alerts independently. In this paper, we give a formal description about attack patterns, attack transition states and attack scenarios. We proposed the system architecture to generate an attack scenario database correctly and completely. We first classify and extract attack patterns, then, correlate attack patterns with pre/post conditions matching and. Moreover, the approach, attack scenario generation with casual relationship (ASGCR), is proposed to build an attack scenario database Finally, we present the combination of our attack scenario database with security operation center (SOC) to implement the related components concerning alert integrations and correlations. It is shown that our method is better than CAML [4] since we can generate more attack scenarios effectively and correctly to help system managers to maintain network security.
Keywords
Internet; computer viruses; database management systems; software architecture; Internet; attack scenario database; attack scenario generation with casual relationship; formal description; high speed network; information era; intrusion detection systems; low-level attacks; security operation center; system architecture; viruses; worms; Communication system security; Data security; Databases; High-speed networks; IP networks; Intrusion detection; National security; Sensor phenomena and characterization; Viruses (medical); Web and internet services;
fLanguage
English
Publisher
ieee
Conference_Titel
Granular Computing, 2007. GRC 2007. IEEE International Conference on
Conference_Location
Fremont, CA
Print_ISBN
978-0-7695-3032-1
Type
conf
DOI
10.1109/GrC.2007.117
Filename
4403126
Link To Document