An Attack Plan Recognition System Based On Multi-alert Fusion

HUANG He,JIANG Xing-hao,CHEN Xiu-zhen,LI Jian-hua
DOI: https://doi.org/10.3969/j.issn.1008-0570.2008.27.012
2008-01-01
Abstract:This paper presents an attack plan recognition system which is based on multi-alert fusion. Based on the vindicability of system status and causality between System alert and IDS alert, this system calculate the confidence of each alert by using Bayesian networks, and then reason about attack plans with the high-reliable evidence we got.
What problem does this paper attempt to address?