Attack Pattern Discovery in Forensic Investigation of Network Attacks

Ying Na Zhu · IEEE Journal on Selected Areas in Communications · 2011

We mine the logs of network traffic data to find the contexts of attacks; we call them attack patterns. We propose an iterative algorithm for discovering attack patterns via a feedback mechanism, with the degrees of belief for attack instances propagated to the next iteration to further refine the search. Our simulations verify that the algorithm achieves accuracy in discovering attack patterns. Our attack pattern discovery has the additional advantage of being an unsupervised algorithm, e.g., it does not require a priori user-defined thresholds.

Read the paper · More papers on PaperTik