Attack scenarios reasoning,hypothesizing and predicting based on capability transition model

Autor: TIAN Zhi-hong, ZHANG Wei-zhe, ZHANG Yong-zheng, ZHANG Hong-li, LI Yang, JIANG Wei
Jazyk: čínština
Rok vydání: 2007
Předmět:
Zdroj: Tongxin xuebao, Pp 78-84 (2007)
Druh dokumentu: article
ISSN: 1000-436X
Popis: To construct attack scenarios and predict intrusion intents automatically,a real-time alert correlation approach based on capability transition model was proposed.By highly abstracting the reasoning evidences,the process complexity is effectively reduced.Experiment results on the DARPA2000 IDS test dataset indicate that the method is effective and efficient.
Databáze: Directory of Open Access Journals