Authors
Jingmin Zhou, Mark Heckman, Brennen Reynolds, Adam Carlson, Matt Bishop
Publication date
2007/2/1
Journal
ACM Transactions on Information and System Security (TISSEC)
Volume
10
Issue
1
Pages
4-es
Publisher
ACM
Description
Signature-based network intrusion-detection systems (NIDSs) often report a massive number of simple alerts of low-level security-related events. Many of these alerts are logically involved in a single multi-stage intrusion incident and a security officer often wants to analyze the complete incident instead of each individual simple alert. This paper proposes a well-structured model that abstracts the logical relation between the alerts in order to support automatic correlation of those alerts involved in the same intrusion. The basic building block of the model is a logical formula called a capability. We use capability to abstract consistently and precisely all levels of accesses obtained by the attacker in each step of a multistage intrusion. We then derive inference rules to define logical relations between different capabilities. Based on the model and the inference rules, we have developed several novel alert correlation …
Total citations
2006200720082009201020112012201320142015201620172018201920202021202220232024141417161620191591325153222
Scholar articles
J Zhou, M Heckman, B Reynolds, A Carlson, M Bishop - ACM Transactions on Information and System Security …, 2007