Alert analysis and threat evaluation in Network Situation Awareness
Juan Wang, Fengli Zhang, Jing Jin, Wei Chen · 2010
In this paper we study on the alert analysis technique of Network Situation Awareness (NSA). The overwhelming alerts make it challenging to understand and manage. Although there are already many alert analysis techniques proposed in Intrusion Detection research area, most of them are used to reduce false positives and false negatives. However, the NSA requires the alert analysis techniques to offer high-level information such as how serious of attacks are and how dangerous of devices are and which attacks or devices need administrator to pay attention to. To address this problem, we propose a time and space based alert analysis technique which can correlate related alerts without background knowledge and offer attack graph to help the administrator understand the attack steps clearly and efficiently. And a threat evaluation is given to find the most dangerous attack, which further saves administrator's time and energy in processing large amount alerts.