计算机应用 ›› 2011, Vol. 31 ›› Issue (05): 1276-1279.DOI: 10.3724/SP.J.1087.2011.01276

• 信息安全 • 上一篇    下一篇

多步攻击告警关联模型构建与实现

翟光群,周双银   

  1. 郑州大学 信息工程学院,郑州450001
  • 收稿日期:2010-11-02 修回日期:2011-01-02 发布日期:2011-05-01 出版日期:2011-05-01
  • 通讯作者: 周双银
  • 作者简介:翟光群(1952-),男,河南伊川人,副教授,CCF会员,主要研究方向:网络安全、计算机控制与测量;周双银(1980-),男,河南南阳人,硕士研究生,主要研究方向:网络安全。
  • 基金资助:

    河南省重点科技攻关项目(0423020300)。

Construction and implementation of multistep attacks alert correlation model

ZHAI Guang-qun, ZHOU Shuang-yin   

  1. School of Information Engineering, Zhengzhou University, Zhengzhou Henan 450001, China
  • Received:2010-11-02 Revised:2011-01-02 Online:2011-05-01 Published:2011-05-01
  • Contact: ZHOU ShuangYin

摘要: 为精简入侵检测系统产生的大量报警信息和分析攻击者的目的和动机,提出了新的报警信息关联模型。该模型通过事件关联把具有相似关系的报警信息关联后存储为元报警,然后根据报警类型知识库转换为超报警,最后根据超报警之间的因果关系进行攻击关联,构建出攻击关联图。实验表明,该模型提高了报警处理效率,对识别攻击意图和提高报警准确性有较好的效果。

关键词: 入侵检测, 报警信息, 多步攻击, 事件关联, 超报警

Abstract: To reduce the number of alerts in Intrusion Detection System (IDS) and uncover attack purposes and motivations, a new alert correlation model was proposed, in which alerts with similarity relationship were correlated by event correlation and stored as meta-alerts, then transformed into hyper-alerts according to the knowledge base rules, and finally hyper-alerts with casual relationship were correlated by attack correlation and an attack correlation graph was formed. The experimental results show that the model raises alert processing efficiency and contributes to attack purposes identification and alert accuracy improvement.

Key words: intrusion detection, alert information, multistep attack, event correlation, hyper alert