• DocumentCode
    2504396
  • Title

    MARS: Multi-stage Attack Recognition System

  • Author

    Alserhani, Faeiz ; Akhlaq, Monis ; Awan, Irfan U. ; Cullen, Andrea J. ; Mirchandani, Pravin

  • Author_Institution
    Inf. Res. Inst., Univ. of Bradford, Bradford, UK
  • fYear
    2010
  • fDate
    20-23 April 2010
  • Firstpage
    753
  • Lastpage
    759
  • Abstract
    Network Intrusion Detection Systems (NIDS) are considered as essential mechanisms to ensure reliable security. Intrusive model is used in signature-based NIDS by defining attack patterns and applying signature-matching on incoming traffic packets. Thousands of signatures and rules are created to specify different attacks and variations of a single attack. As a result, enormous data with less efficiency is produced that overwhelms the network administrator. Most of the generated alerts are false-positives; this is due to the redundancy caused by the detection techniques, and due to low-level processing capacity. Moreover, detection of novel and multi-stage attacks are not efficiently achieved by the current systems. Hence, high-level view of the attacker´s behaviour has become a stressing demand. Alerts correlation techniques have been widely used to provide intelligent and stateful detection methodologies. This is to understand attack steps and predict the expected sequence of events. However, most of the proposed systems are based on rules libraries specified by security experts, which is a cumbersome and error prone task. Other methods are based on statistical models; these are unable to identify causal relationships between the events. In this paper, we identify the limitations of the current techniques and propose a framework for alert correlation that overcomes these shortcomings. An improved “cause and effect” model will be presented cooperating with statistical model to achieve higher detection rate with minimum false positives. Knowledge-based model with vulnerability and extensional consequences parameters has been developed to provide manageable and meaningful graph. The proposed system is evaluated using DARPA 2000 and collected real life data sets. The results have shown an improvement in respect to detection rate and reduction of false positives.
  • Keywords
    security of data; DARPA 2000; alerts correlation techniques; attack patterns; detection techniques; extensional consequences parameters; knowledge-based model; low-level processing capacity; multistage attack recognition system; network intrusion detection systems; signature-based NIDS; signature-matching; Data mining; Data security; Informatics; Intrusion detection; Knowledge management; Libraries; Mars; Redundancy; Telecommunication traffic; Traffic control; Alerts correlation; Network intrusion detection systems; multi-stage attack;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Advanced Information Networking and Applications (AINA), 2010 24th IEEE International Conference on
  • Conference_Location
    Perth, WA
  • ISSN
    1550-445X
  • Print_ISBN
    978-1-4244-6695-5
  • Type

    conf

  • DOI
    10.1109/AINA.2010.57
  • Filename
    5474796