Alerts Information Association Analysis Technology Based on Intrusion Intention

SHI Liang,WANG Beizhan,YAO Junfeng
DOI: https://doi.org/10.3969/j.issn.1000-3428.2006.14.048
2006-01-01
Abstract:This paper presents an alerts association analysis technology based on intrusion intention in order to overcome the problems exited in today's alerts association analysis technologies.This method not only inherits the merits of the alerts association analysis technology based on intrusion strategy such as foreseeable,but also improves the adaptability of the intrusion strategy model.Furthermore,it gives the“skipping step”analysis mechanism and its improvement on the comprehension ability of the intrusion detection system.
What problem does this paper attempt to address?