• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Mao, Beifeng (Mao, Beifeng.) | Liu, Jing (Liu, Jing.) | Lai, Yingxu (Lai, Yingxu.) (Scholars:赖英旭) | Sun, Motong (Sun, Motong.)

Indexed by:

EI Scopus SCIE

Abstract:

Most attacks on the Internet are progressive attacks and exploit multiple nodes. Traditional Intrusion Detection Systems (IDS) cannot detect the original attack node, making it difficult to block the attack at its source. This paper focuses on using IDS' alerts corresponding to abnormal traffic to correlate attacks detected by the IDS, reconstruct multi-step attack scenarios and discover attack chains. Due to many false positives in the information provided by IDS, accurate reconstruction of the attack scenario and extraction of the most critical attack chain is challenging. Therefore, we propose a method to reconstruct multi-step attack scenarios in the network based on multiple information fusion of attack time, risk assessment and attack node information. First, we propose a Convolution and Agent Decision Tree Network (CTnet), a convolutional neural network that evaluates the attacks detected by the IDS and gives an alert with an attack risk assessment. Then, we reconstruct the weighted attack scenario by applying Graph-based Fusion Module (GM) on the captured attacks' risk assessment and time information. Finally, we extract the high-risk attack chain by Depth First Search with Time and Weight (TW-DFS) algorithm. The experimental results show that the proposed method can accurately reconstruct multi-step attack scenarios and trace them back to the original host. It can help administrators to deploy security measures more effectively to ensure the overall security of the network.

Keyword:

Multi-information fusion Attack scenarios reconstruction Interpretable neural network Multi-step attack

Author Community:

  • [ 1 ] [Mao, Beifeng]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing 100124, Peoples R China
  • [ 2 ] [Liu, Jing]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing 100124, Peoples R China
  • [ 3 ] [Lai, Yingxu]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing 100124, Peoples R China
  • [ 4 ] [Sun, Motong]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing 100124, Peoples R China
  • [ 5 ] [Lai, Yingxu]Minist Educ, Engn Res Ctr Intelligent Percept & Autonomous Con, Beijing 100124, Peoples R China

Reprint Author's Address:

  • 赖英旭

    [Lai, Yingxu]Beijing Univ Technol, Coll Comp Sci, Fac Informat Technol, Beijing 100124, Peoples R China;;[Lai, Yingxu]Minist Educ, Engn Res Ctr Intelligent Percept & Autonomous Con, Beijing 100124, Peoples R China

Show more details

Related Keywords:

Source :

COMPUTER NETWORKS

ISSN: 1389-1286

Year: 2021

Volume: 198

5 . 6 0 0

JCR@2022

ESI Discipline: COMPUTER SCIENCE;

ESI HC Threshold:87

JCR Journal Grade:1

Cited Count:

WoS CC Cited Count: 18

SCOPUS Cited Count: 40

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 1

Affiliated Colleges:

Online/Total:900/6350416
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.