首页> 美国政府科技报告 >Building Scenarios from a Heterogeneous Alert Stream.
【24h】

Building Scenarios from a Heterogeneous Alert Stream.

机译:从异构警报流构建方案。

获取原文

摘要

We describe a real-time algorithm for combining the alerts produced by several heterogeneous intrusion detection sensors into scenarios. Each scenario represents a sequence of actions performed by a single actor or organization. Our algorithm, which is probabilistic in nature, can determine the scenario membership of a new alert in time proportional to the number of candidate scenarios. It is capable of finding scenarios even if an intruder has used stealthy attack methods such as forged source IP addresses or long latencies between attack components.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号