Construction and implementation of multistep attacks alert correlation model
Zhou Shuang-yin · Journal of Computer Applications · 2011
To reduce the number of alerts in Intrusion Detection System(IDS) and uncover attack purposes and motivations,a new alert correlation model was proposed,in which alerts with similarity relationship were correlated by event correlation and stored as meta-alerts,then transformed into hyper-alerts according to the knowledge base rules,and finally hyper-alerts with casual relationship were correlated by attack correlation and an attack correlation graph was formed.The experimental results show that the model raises alert processing efficiency and contributes to attack purposes identification and alert accuracy improvement.