Research on discovering multi-step attack patterns based on clustering IDS alert sequences
A method of discovering multi-step attack patterns from alert data was studied.Alert similarity function was defined to construct the set of attack activity sequences.Sequence alignment technology was used to cluster the similar attack activity sequences.Multi-step attack patterns in a cluster were...
Saved in:
Main Authors: | MEI Hai-bin1, GONG Jian1, ZHANG Ming-hua2 |
---|---|
Format: | Article |
Language: | zho |
Published: |
Editorial Department of Journal on Communications
2011-01-01
|
Series: | Tongxin xuebao |
Subjects: | |
Online Access: | http://www.joconline.com.cn/zh/article/74418776/ |
Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
-
Research on alert correlation method based on alert confidence in multi-IDS environment
by: MEI Hai-bin, et al.
Published: (2011-01-01) -
Using fuzzy clustering to reconstruct alert correlation graph of intrusion detection
by: MA Lin-ru1, et al.
Published: (2006-01-01) -
IDS alert clustering algorithm based on chaotic particle swarm optimization
by: Xiao-bo XU, et al.
Published: (2013-03-01) -
Alert processing based on attack graph and multi-source analyzing
by: Wei-xin LIU, et al.
Published: (2015-09-01) -
Research on attack scenario reconstruction method based on causal knowledge discovery
by: Di FAN, et al.
Published: (2017-04-01)