Title: A novel technique of recognising multi-stage attack behaviour

Authors: Li Wang, Yao Li, Zhi-tang Li

Addresses: Department of Computer Science, Huazhong University of Science and Technology, Hubei Wuhan 430074, China; Department of Computer Science, University of New Brunswick, Fredericton, P.O. Box 4400 New Brunswick, E3B 5A3 Canada. ' Department of Computer Science, University of New Brunswick, Fredericton, P.O. Box 4400 New Brunswick, E3B 5A3 Canada. ' Department of Computer Science, Huazhong University of Science and Technology, Hubei Wuhan 430074, China

Abstract: With the increasing amount of security audit data, management and analysis of it become a critical and challenging issue. Security alerts and threat analysis project (SATA) aims at analysing security events and detecting security threat. In this paper, we proposed a novel method of constructing attack scenarios in order to recognise multi-stage attack behaviours and predict next potential attack steps of the attacker. Our method based on statistical method using the feature of time consecution association between contextual attack steps. Besides, we proposed a new method of computing the correlativity between two contextual alerts which enhances the correlation-ship of the attack steps constructing attack scenario models and ensures the accuracy of the final correlation result. The idea is easy to implement and can be used to detect novel multi-stage attacks. Experiment shows that our method is effective and feasible.

Keywords: multi-stage attacks; attack plan recognition; security alerts; correlativity; threat analysis; security threats; intrusion detection.

DOI: 10.1504/IJHPCN.2010.037791

International Journal of High Performance Computing and Networking, 2010 Vol.6 No.3/4, pp.174 - 180

Published online: 30 Dec 2010 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article