Research on Causal Correlation of Alerts with Confidence Measurement

唐婵娜,范磊
DOI: https://doi.org/10.3969/j.issn.1009-8054.2009.06.031
2009-01-01
Abstract:A successful network attack is usually composed of different attacks in different stages, with the early ones preparing for the later ones.In the method of causal correlating, intrusion alerts are correlated by using prerequisites and consequences of the corresponding attacks so as to reconstruct attack scenarios.In this paper, confidence measurement is introduced as an attribute of correlation between alerts, thus to analyze the reliability of causal correlation and reduce the false correlations.The desired results have been obtained in the experiment using the standard data set DARPA.
What problem does this paper attempt to address?