A privacy-preserving multi-step attack correlation algorithm
Minyi Xian, Yongtang Zhang · 2016
Traditional multi-step attack correlation approaches based on intrusion alerts face the challenge of recognizing attack scenarios because these approaches require complex pre-defined association rules as well as a high dependency on expert knowledge. Meanwhile, they barely consider the privacy issues. Under such circumstance, a novel algorithm is proposed to construct multi-step attack scenarios based on discovering attack behavior sequential patterns. It analyzes time sequential characteristics of attack behaviors and implements a support evaluation method. An optimized candidate attack sequence generation method is applied to solve the problem of pre-defined association rules complexity as well as expert knowledge dependency. An enhanced k-anonymity method is applied on this algorithm to realize privacy-preserving feature Experimental results indicate that the algorithm has comparatively better performance and accuracy on multi-step attack correlation and reaches a well balance between efficiency and privacy issues.