首页> 外文会议>Information Technology: Research and Education, 2005. ITRE 2005. 3rd International Conference on >Frame-based attack representation and real-time first order logic automatic reasoning
【24h】

Frame-based attack representation and real-time first order logic automatic reasoning

机译:基于帧的攻击表示和实时一阶逻辑自动推理

获取原文

摘要

Internet has grown by several orders of magnitude in recent years, prompting network security as a great concern. Hence, intrusion detection systems (IDSs) are used to timely detect intrusions and defend against attack attempts. However, the current IDS technology generates a huge volume of alert events due to false alarm alerts, and requires costly alert manual reviewing due to the lack of intelligence in IDS. As a solution, security information management (SIM) is a growing area of interest in network security. In this paper, we propose FAR-FAR (frame-based attack representation and first-order logic automatic reasoning) system in SIM to relieve the administrator from the time-consuming and costly alert manual reviewing. With the backward-chaining, FAR-FAR can make real-time reasoning for network attack scenarios. In FAR-FAR, the aggregated alerts from different IDS agents are converted into uniform frame-structured streams by case grammar. Afterwards, first-order logic production rules are used to extract the hidden attack scenarios. Our simulation results show that FAR-FAR's attack scenario reasoning rate for the incoming alerts are generally far less than the incoming alerts' inter-arrival time. This guarantees FAR-FAR to automatically reason the attack plans in real time and predict possible attack attempts at an early stage.
机译:近年来,Internet已增长了几个数量级,这引起了网络安全性的极大关注。因此,入侵检测系统(IDS)用于及时检测入侵并防御攻击企图。但是,当前的IDS技术由于虚假警报而产生大量警报事件,并且由于IDS缺乏智能,因此需要进行昂贵的警报人工检查。作为一种解决方案,安全信息管理(SIM)是网络安全领域中日益受到关注的领域。在本文中,我们提出了SIM中的FAR-FAR(基于帧的攻击表示和一阶逻辑自动推理)系统,以减轻管理员从费时且昂贵的警报人工审核中的负担。通过反向链接,FAR-FAR可以对网络攻击情形进行实时推理。在FAR-FAR中,通过案例语法将来自不同IDS代理的汇总警报转换为统一的帧结构流。然后,使用一阶逻辑产生规则提取隐藏的攻击方案。我们的仿真结果表明,FAR-FAR对传入警报的攻击情景推理率通常远小于传入警报的到达间隔时间。这保证了FAR-FAR能够自动实时地实时制定攻击计划并在早期阶段预测可能的攻击尝试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号