An Alert Hierarchical Association Algorithm To Construct Attack Scenarios

Shuai Chunyan,Jiang Jianhui,Ouyang Xin,Chen Linbo,Yang Yang
2012-01-01
Abstract:At present most intrusion detection systems ignored the logic relationships between attacks,so it leads to high false positive rate.In this paper multi-attribute of attack behaviors are analyzed and attacks are classified into different classes. A related attack knowledge database is built. The paper creates attack association rules and absent attack inference rules, and applies an alert hierarchical associate algorithm to correlate alerts based on the causative relationships between attacks. Experiments are conducted to verify the correctness and effectiveness of the proposed algorithm.
What problem does this paper attempt to address?