IDS alerts correlation using grammar-based approach

被引:16
|
作者
Al-Mamory, Safaa O. [1 ]
Zhang, Hongli [1 ]
机构
[1] Harbin Inst Technol, Sch Comp Sci & Technol, Harbin 150001, Peoples R China
关键词
D O I
10.1007/s11416-008-0103-3
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection System (IDS) is a security technology that attempts to identify intrusions. Defending against multi-step intrusions which prepare for each other is a challenging task. In this paper, we propose a novel approach to alert post-processing and correlation, the Alerts Parser. Different from most other alert correlation methods, our approach treats the alerts as tokens and uses modified version of the LR parser to generate parse trees representing the scenarii in the alerts. An Attribute Context-Free Grammar (ACF-grammar) is used for representing the multi-step attacks. Attack scenarii information and prerequisites/consequences knowledge are included together in the ACF-grammar enhancing the correlation results. The modified LR parser depends on these ACF-grammars to generate parse trees. The experiments were performed on two different sets of network traffic traces, using different open-source and commercial IDS sensors. The discovered scenarii are represented by Correlation Graphs (CGs). The experimental results show that Alerts Parser can work in parallel, effectively correlate related alerts with low false correlation rate, uncover the attack strategies, and generate concise CGs.
引用
收藏
页码:271 / 282
页数:12
相关论文
共 50 条
  • [1] Evaluation of Text Quality Using a Grammar-Based Approach
    Hu, Zhenwen
    [J]. BASIC & CLINICAL PHARMACOLOGY & TOXICOLOGY, 2020, 126 : 335 - 335
  • [2] Modeling Alerts for IDS Correlation
    Roschke, Sebastian
    Cheng, Feng
    Meinel, Christoph
    [J]. JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2011, 6 (02): : 98 - 105
  • [3] A Grammar-Based Approach to Invertible Programs
    Matsuda, Kazutaka
    Mu, Shin-Cheng
    Hu, Zhenjiang
    Takeichi, Masato
    [J]. PROGRAMMING LANGUAGES AND SYSTEMS, PROCEEDINGS, 2010, 6012 : 448 - +
  • [4] A grammar-based approach to synonym analysis
    Bulonkov, MA
    Kochetov, DV
    [J]. PROGRAMMING AND COMPUTER SOFTWARE, 1996, 22 (03) : 126 - 133
  • [5] A Statistical, Grammar-Based Approach to Microplanning
    Gardent, Claire
    Perez-Beltrachini, Laura
    [J]. COMPUTATIONAL LINGUISTICS, 2017, 43 (01) : 1 - 30
  • [6] Correlation analysis system using VA data, IDS alerts
    Lee, Jong-Hyouk
    Chung, Tai-Myung
    [J]. Advances in Computational Methods in Sciences and Engineering 2005, Vols 4 A & 4 B, 2005, 4A-4B : 1600 - 1603
  • [7] A graph grammar-based approach for graph layout
    Liu, Yufeng
    Zeng, Xiaoqin
    Zou, Yang
    Zhang, Kang
    [J]. SOFTWARE-PRACTICE & EXPERIENCE, 2018, 48 (09): : 1523 - 1535
  • [8] Fast Grammar-Based Evolution Using Memoization
    Luerssen, Martin
    Powers, David
    [J]. PARALLEL PROBLEM SOLVING FROM NATURE-PPSN XI, PT II, 2010, 6239 : 502 - 511
  • [9] On the sufficiency of time-based correlation for signature-based IDS alerts
    Neville, SW
    [J]. 2003 IEEE PACIFIC RIM CONFERENCE ON COMMUNICATIONS, COMPUTERS, AND SIGNAL PROCESSING, VOLS 1 AND 2, CONFERENCE PROCEEDINGS, 2003, : 836 - 839
  • [10] A hybrid grammar-based approach to multimodal languages specification
    D'Ulizia, Arianna
    Ferri, Fernando
    Grifoni, Patrizia
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2007: OTM 2007 WORKSHOPS, PT 1, PROCEEDINGS, 2007, 4805 : 367 - +