TY - GEN
T1 - Modeling network attacks for scenario construction
AU - Al-Mamory, Safaa O.
AU - Zhang, Hongli
AU - Abbas, Ayad R.
PY - 2008
Y1 - 2008
N2 - The Intrusion detection system (IDS) is a security technology that attempts to identify network intrusions. Defending against multistep intrusions which prepare for each other is a challenging task. In this paper, the Context-Free Grammar (CFG) was used to describe the multistep attacks using alerts classes. Based on the CFCs, the modified LR parser was employed to generate the parse trees of the scenarios presented in the alerts. Instead of searching all the received alerts for those that prepare for a new alert, we only search for the latest alert's type of each scenario. Consequently, the proposed system has an attractive time complexity. The experiments were performed on two different sets of network traffic traces, using different open-source and commercial IDSs. The detected scenarios are represented by Correlation Graphs (CGs). The experimental results show that the CFG can describe multistep attacks explicitly and the modified LR parser, based on the CFG, can construct scenarios successfully.
AB - The Intrusion detection system (IDS) is a security technology that attempts to identify network intrusions. Defending against multistep intrusions which prepare for each other is a challenging task. In this paper, the Context-Free Grammar (CFG) was used to describe the multistep attacks using alerts classes. Based on the CFCs, the modified LR parser was employed to generate the parse trees of the scenarios presented in the alerts. Instead of searching all the received alerts for those that prepare for a new alert, we only search for the latest alert's type of each scenario. Consequently, the proposed system has an attractive time complexity. The experiments were performed on two different sets of network traffic traces, using different open-source and commercial IDSs. The detected scenarios are represented by Correlation Graphs (CGs). The experimental results show that the CFG can describe multistep attacks explicitly and the modified LR parser, based on the CFG, can construct scenarios successfully.
UR - https://www.scopus.com/pages/publications/56349086152
U2 - 10.1109/IJCNN.2008.4633994
DO - 10.1109/IJCNN.2008.4633994
M3 - 会议稿件
AN - SCOPUS:56349086152
SN - 9781424418213
T3 - Proceedings of the International Joint Conference on Neural Networks
SP - 1495
EP - 1502
BT - 2008 International Joint Conference on Neural Networks, IJCNN 2008
T2 - 2008 International Joint Conference on Neural Networks, IJCNN 2008
Y2 - 1 June 2008 through 8 June 2008
ER -