Research on Intrusion Scenarios Building Based on Multiple Hypothesis Tracking

LI Hui,ZHENG Qing-hua,HAN Chong-zhao,GUAN Xiao-hong
DOI: https://doi.org/10.3321/j.issn:1000-436x.2005.04.013
2005-01-01
Abstract:A fuzzy multiple hypothesis intrusion scenarios building algorithm was proposed based on multiple hypothesis tracking(MHT)theory which originated from information fusion. The algorithm could automatically analyze and organize alarms produced by intrusion detection systems to form credible attack segments and finally generate intrusion scenarios. The whole process can be divided into three steps, which were hypothesis generation, fuzzy hypothesis assessment and hypothesis management. Experiments on the DARPA2000 IDS test dataset show that the algorithm is effective and efficient.
What problem does this paper attempt to address?