A Model Towards Using Evidence from Security Events for Network Attack Analysis

Changwei Liu, Anoop Singhal, Duminda Wijesekera · 2014

Constructing an efficient and accurate model from security events to determine an attack scenario for an enterprise network is challenging. In this paper, we discuss how to use the information obtained from security events to construct an attack scenario and build an evidence graph. To achieve the accuracy and completeness of the evidence graph, we use Prolog inductive and abductive reasoning to correlate evidence by reasoning the causality, and use an anti-forensics database and a corresponding attack graph to find the missing evidence. 1.

Read the paper · More papers on PaperTik