DocumentCode :
2386943
Title :
Generating Attack Scenarios with Causal Relationship
Author :
Cheng, Yu-Chin ; Chen, Chien-Hung ; Chiang, Chung-Chih ; Wang, Jun-Wei ; Laih, Chi-Sung
Author_Institution :
Nat. Cheng Kung Univ., Tainan
fYear :
2007
fDate :
2-4 Nov. 2007
Firstpage :
368
Lastpage :
368
Abstract :
With the incoming of information era, Internet has been developed rapidly and offered more and more services. However, intrusions, viruses and worms follow with the grown of Internet, spread widely all over the world within high speed network. Although many kinds of intrusion detection systems (IDSs) are developed, they have some disadvantages in that they focus on low-level attacks or anomalies, and raise alerts independently. In this paper, we give a formal description about attack patterns, attack transition states and attack scenarios. We proposed the system architecture to generate an attack scenario database correctly and completely. We first classify and extract attack patterns, then, correlate attack patterns with pre/post conditions matching and. Moreover, the approach, attack scenario generation with casual relationship (ASGCR), is proposed to build an attack scenario database Finally, we present the combination of our attack scenario database with security operation center (SOC) to implement the related components concerning alert integrations and correlations. It is shown that our method is better than CAML [4] since we can generate more attack scenarios effectively and correctly to help system managers to maintain network security.
Keywords :
Internet; computer viruses; database management systems; software architecture; Internet; attack scenario database; attack scenario generation with casual relationship; formal description; high speed network; information era; intrusion detection systems; low-level attacks; security operation center; system architecture; viruses; worms; Communication system security; Data security; Databases; High-speed networks; IP networks; Intrusion detection; National security; Sensor phenomena and characterization; Viruses (medical); Web and internet services;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Granular Computing, 2007. GRC 2007. IEEE International Conference on
Conference_Location :
Fremont, CA
Print_ISBN :
978-0-7695-3032-1
Type :
conf
DOI :
10.1109/GrC.2007.117
Filename :
4403126
Link To Document :
بازگشت