Attack modeling using colored petri net and alerts correlation algorithms design
CSTR:
Author:
Affiliation:

Clc Number:

Fund Project:

  • Article
  • |
  • Figures
  • |
  • Metrics
  • |
  • Reference
  • |
  • Related
  • |
  • Cited by
  • |
  • Materials
  • |
  • Comments
    Abstract:

    In order to improve the alerts quality and prediction capability of traditional intrusion detection systems (IDS), the advanced alerts correlation algorithms are proposed, which is based on attack scenarios modeling using colored petri net (CPN). The current analysis approach information filtering is updated to messages logic deduction by reasoning under the model. The alert and the attack are converted to two different parameters for computation. By means of transforming CPN model and calculating the minimal covering set, the algorithms for multi-step attack and cooperative attack are designed. The experimental alerts correlation analysis system (ACAS) is programmed. That experiment results indicate that these algorithms could be applied to improve the alerts quality and prediction ability of IDS effectively.

    Reference
    Related
    Cited by
Get Citation

杜建军,吴中福,陈明. CPN攻击建模及警报相关性算法设计[J].重庆大学学报,2011,34(4):118~124

Copy
Related Videos

Share
Article Metrics
  • Abstract:
  • PDF:
  • HTML:
  • Cited by:
History
  • Received:September 10,2010
  • Revised:
  • Adopted:
  • Online:
  • Published:
Article QR Code