pdf

Multi-step attack alert correlation method based on CPN

  • 2013-09-20
  • 132.56KB
  • Points it Requires : 2

Based on the study of Colored Petri Net (CPN) theory, in order to address the \"alarm fatigue\" problem of current intrusion detection, a CPN attack template is constructed that is divided according to the permissions that the intruder can obtain. By sequentially correlating low-level, discrete alarm information, the entire process of a multi-step attack is presented. This association method only uses a limited number of templates and is simpler and easier to implement than previous methods. At the same time, security personnel can predict and evaluate the security status of the network from the perspective of the intruder\'s ability to acquire attacks. Keywords: Colored Petri Net; Multi-step attack; Permission; Alarm association

unfold

You Might Like

Uploader
justyouandmehr
 

Recommended ContentMore

Popular Components

Just Take a LookMore

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号
×