A Threat Prediction Framework for Network Security Based on Attack Patterns and Colored Petri Nets

被引:0
|
作者
Chien, Sheng-Hui [1 ]
Ho, Cheng-Seen [2 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Elect Engn, Taipei, Taiwan
[2] Tuangnan Univ, Dept Informat Technol & Commun, Taipei, Taiwan
关键词
Attack pattern; network security situation awareness; situation assessment; threat prediction; colored Petri Net;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
It is hard to comprehend intrusion alerts because many attacks are multistage and even coordinated by multiple attackers. This paper introduces a threat prediction framework to tackle the problem. The framework adopts attack patterns to facilitate the reuse of network security knowledge. The instantiation of relevant attack patterns becomes a network specific attack plan. We developed a colored Petri Net, CPNap, to represent the attack plan, which can clearly reveal the attack steps and security states. A CPNap is then tokenized to represent an actual attack. Based on the token arrival probability of a tokenized CPNap, we finally can conduct situation assessment and threat prediction. Our experiments show the framework can effectively predict security threats of multistage attacks and identify cooperating attackers. With this, network defenders may have a better chance to take mitigation actions before the attackers fulfill their malicious intentions.
引用
收藏
页码:492 / 496
页数:5
相关论文
共 50 条
  • [1] An Attack Modeling Based on Hierarchical Colored Petri Nets
    Wu, Ruoyu
    Li, Weiguo
    Huang, He
    [J]. ICCEE 2008: PROCEEDINGS OF THE 2008 INTERNATIONAL CONFERENCE ON COMPUTER AND ELECTRICAL ENGINEERING, 2008, : 918 - 921
  • [2] Security Analysis on Railway Network Time Protocol Based on Colored Petri Nets
    Zhang, Youpeng
    Zhang, Haolei
    Wang, Hong
    [J]. Tiedao Xuebao/Journal of the China Railway Society, 2017, 39 (10): : 82 - 88
  • [3] Colored Petri Nets Based Modeling of Information Flow Security
    Wu, Ruoyu
    Li, Weiguo
    Huang, He
    [J]. WKDD: 2009 SECOND INTERNATIONAL WORKSHOP ON KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2009, : 681 - 684
  • [4] A Coloured Petri Nets Based Attack Tolerance Framework
    Zhou, Wenbo
    Dague, Philippe
    Liu, Lei
    Ye, Lina
    Zaidi, Fatiha
    [J]. 2020 27TH ASIA-PACIFIC SOFTWARE ENGINEERING CONFERENCE (APSEC 2020), 2020, : 159 - 168
  • [5] Attack composition model based on generalized stochastic colored petri nets
    State Key Laboratory of Mathematical Engineering and Advanced Computing, PLA Information Engineering University, Zhengzhou 450002, China
    [J]. Gao, X. (feiyu4321@163.com), 2013, Science Press (35):
  • [6] A network attack model based on colored Petri net
    Li, Xinlei
    Li, Di
    [J]. Journal of Networks, 2014, 9 (07) : 1883 - 1891
  • [7] Component-Based Security Policy Design with Colored Petri Nets
    Huang, Hejiao
    Kirchner, Helene
    [J]. SEMANTICS AND ALGEBRAIC SPECIFICATION: ESSAYS DEDICATED TO PETER D. MOSSES ON THE OCCASION OF HIS 60TH BIRTHDAY, 2009, 5700 : 21 - +
  • [8] A context inference framework based on fuzzy colored timed Petri nets
    Lee, Keon Myung
    Hwang, Kyoung-Soon
    Lee, Chan Hee
    [J]. PROCEEDINGS OF THE 9TH WSEAS INTERNATIONAL CONFERENCE ON MATHEMATICAL AND COMPUTATIONAL METHODS IN SCIENCE AND ENGINEERING (MACMESE '07)/ DNCOCO '07, 2007, : 458 - 463
  • [9] Performance Prediction for SaaS Deployment Optimization Based on Colored Petri Nets
    Gong, Zhiyuan
    Ying, Shi
    Li, Lin
    Jia, Xiangyang
    Zhang, Long
    [J]. PROCEEDINGS 2013 INTERNATIONAL CONFERENCE ON MECHATRONIC SCIENCES, ELECTRIC ENGINEERING AND COMPUTER (MEC), 2013, : 2689 - 2693
  • [10] Formal Specification and Verification of Modular Security Policy Based on Colored Petri Nets
    Huang, Hejiao
    Kirchner, Helene
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2011, 8 (06) : 852 - 865