Skip to main navigation Skip to search Skip to main content

Modeling network attacks for scenario construction

  • Harbin Institute of Technology
  • Wuhan Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

The Intrusion detection system (IDS) is a security technology that attempts to identify network intrusions. Defending against multistep intrusions which prepare for each other is a challenging task. In this paper, the Context-Free Grammar (CFG) was used to describe the multistep attacks using alerts classes. Based on the CFCs, the modified LR parser was employed to generate the parse trees of the scenarios presented in the alerts. Instead of searching all the received alerts for those that prepare for a new alert, we only search for the latest alert's type of each scenario. Consequently, the proposed system has an attractive time complexity. The experiments were performed on two different sets of network traffic traces, using different open-source and commercial IDSs. The detected scenarios are represented by Correlation Graphs (CGs). The experimental results show that the CFG can describe multistep attacks explicitly and the modified LR parser, based on the CFG, can construct scenarios successfully.

Original languageEnglish
Title of host publication2008 International Joint Conference on Neural Networks, IJCNN 2008
Pages1495-1502
Number of pages8
DOIs
StatePublished - 2008
Event2008 International Joint Conference on Neural Networks, IJCNN 2008 - Hong Kong, China
Duration: 1 Jun 20088 Jun 2008

Publication series

NameProceedings of the International Joint Conference on Neural Networks

Conference

Conference2008 International Joint Conference on Neural Networks, IJCNN 2008
Country/TerritoryChina
CityHong Kong
Period1/06/088/06/08

Fingerprint

Dive into the research topics of 'Modeling network attacks for scenario construction'. Together they form a unique fingerprint.

Cite this