Real-Time Alert Correlation with Type Graphs

被引:0
|
作者
Tedesco, Gianni [1 ]
Aickelin, Uwe [1 ]
机构
[1] Univ Nottingham, Sch Comp Sci, Nottingham NG8 1BB, England
来源
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The premise of automated alert correlation is to accept that false alerts from a low level intrusion detection system are inevitable and use attack models to explain the output in an understandable way. Several algorithms exist for this purpose which use attack graphs to model the ways in which attacks can be combined. These algorithms can be classified in to two broad categories namely scenario-graph approaches, which create an attack model starting from a vulnerability assessment and type-graph approaches which rely on an abstract model of the relations between attack types. Solve research in to improving the efficiency of type-graph correlation has been carried out but this research has ignored the hypothesizing of missing alerts. Our work is to present a novel type-graph algorithm which unifies correlation and hypothesizing in to a single operation. Our experimental results indicate that the approach is extremely efficient in the face of intensive alerts and produces compact output graphs comparable to other techniques.
引用
收藏
页码:173 / 187
页数:15
相关论文
共 50 条
  • [41] Real-time Analytics for Fast Evolving Social Graphs
    Wickramaarachchi, Charith
    Kumbhare, Alok
    Frincu, Marc
    Chelmis, Charalampos
    Prasanna, Viktor K.
    [J]. 2015 15TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING, 2015, : 829 - 834
  • [42] Transforming Real-Time Task Graphs to Improve Schedulability
    Gu, Chuancai
    Guan, Nan
    Feng, Zhiwei
    Deng, Qingxu
    Hu, Xiaobo Sharon
    Yi, Wang
    [J]. 2016 IEEE 22ND INTERNATIONAL CONFERENCE ON EMBEDDED AND REAL-TIME COMPUTING SYSTEMS AND APPLICATIONS (RTCSA), 2016, : 29 - 38
  • [43] Polyp-Alert: Near real-time feedback during colonoscopy
    Wang, Yi
    Tavanapong, Wallapak
    Wong, Johnny
    Oh, Jung Hwan
    de Groen, Piet C.
    [J]. COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2015, 120 (03) : 164 - 179
  • [44] Real-time Fall Detection and Alert System Using Post Estimation
    Safarzadeh, Meysam
    Alborzi, Yusef
    Ardekany, Ali Naiafi
    [J]. 2019 7TH INTERNATIONAL CONFERENCE ON ROBOTICS AND MECHATRONICS (ICROM 2019), 2019, : 508 - 511
  • [45] Scheduling imprecise task graphs for real-time applications
    Ravindran, R. C.
    Krishna, C. Mani
    Koren, Israel
    Koren, Zahava
    [J]. INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2014, 6 (01) : 73 - 85
  • [46] Spammer Detection for Real-Time Big Data Graphs
    Eom, Chris Soo-Hyun
    Lee, James Jung-hun
    Lee, Wookey
    Kim, Jinho
    [J]. 2016 INT IEEE CONFERENCES ON UBIQUITOUS INTELLIGENCE & COMPUTING, ADVANCED & TRUSTED COMPUTING, SCALABLE COMPUTING AND COMMUNICATIONS, CLOUD AND BIG DATA COMPUTING, INTERNET OF PEOPLE, AND SMART WORLD CONGRESS (UIC/ATC/SCALCOM/CBDCOM/IOP/SMARTWORLD), 2016, : 1227 - 1227
  • [47] Real-time scheduling using compact task graphs
    Gupta, R
    Mosse, D
    Suchoza, R
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS, 1996, : 55 - 62
  • [48] Estimating Correlation for a Real-Time Measure of Connectivity
    Arunkumar, Akhil
    Panday, Ashish
    Joshi, Bharat
    Ravindran, Arun
    Zaveri, Hitten P.
    [J]. 2012 ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2012, : 5190 - 5193
  • [49] Real-time correlation of network security alerts
    Li, Zhitang
    Zhang, Aifang
    Lei, Jie
    Wang, Li
    [J]. ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 73 - +
  • [50] A correlation retina for real-time pattern recognition
    Lamalle, B
    Cathebras, G
    Voon, LFCLY
    Gorria, P
    Bellach, B
    Aubreton, O
    [J]. ETFA 2001: 8TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOL 2, PROCEEDINGS, 2001, : 367 - 372