A realistic graph‐based alert correlation system
Ouissem Ben Fredj · Security and Communication Networks · 2015
Abstract This paper introduces a graph‐based attack description that comes with different analysis methods for alert correlation. The system encompasses an attack scenario detection method, an alert correlation method that recognizes multistep attacks, and graph‐based classification method to extract different types of alerts. The performance analysis shows that the system can correlate a huge number of alerts (more than 442 000 alerts) into a dozens of attack graphs. The attack graph has permitted us to extract several attack properties with high precision. Copyright © 2015 John Wiley & Sons, Ltd.