Based on the study of Colored Petri Net (CPN) theory, in order to address the \"alarm fatigue\" problem of current intrusion detection, a CPN attack template is constructed that is divided according to the permissions that the intruder can obtain. By sequentially correlating low-level, discrete alarm information, the entire process of a multi-step attack is presented. This association method only uses a limited number of templates and is simpler and easier to implement than previous methods. At the same time, security personnel can predict and evaluate the security status of the network from the perspective of the intruder\'s ability to acquire attacks. Keywords: Colored Petri Net; Multi-step attack; Permission; Alarm association
You Might Like
Recommended ContentMore
Open source project More
Popular Components
Searched by Users
Just Take a LookMore
Trending Downloads
Trending ArticlesMore