Scenario Recognition based on Collaborative Attack Modeling in Intrusion Detection
Xuejiao Liu, Debao Xiao, Ting Gu · 2008
Abstract — Recently, intrusion detection products have become widely available, and are beginning to gain acceptance as a worthwhile investment for network security. However, traditional intrusion detection systems (IDSs) only focus on low-level attacks and raise alerts independently, though there may be logical connections between them. At the same time, the amount of alerts becomes unmanageable including actual alerts mixed with false alerts. To address that problem, several approaches for alert correlation and attack modeling have been proposed these years. In this paper, we suggest collaborative attack modeling of general attack pattern for constructing multistep attack scenario, based on attack classification. The purpose is then to enable attack-attribute aggregation that make low-level alerts to high-level aggregated ones from heterogeneous IDS systems. In order to better construct complete scenario, causal correlation based on time series and statistical analysis is introduced to facilitate scenario recognition. Through the experimental results with DARPA Data Sets 2000 from Lincoln laboratory, it demonstrates the potential of the proposed approach as well as the effectiveness of our techniques. Index Terms—alert correlation, attack modeling, collaborative