Alert correlation analysis based on attack path graph
Daojuan Zhang, Kexiang Qian, Peng Zhang, Shu Mao, Hongbin Wu · 2017
Alert correlation analysis is trending to be an im-portant part of the cyber security currently. However, the existing approaches have shortcomings to analyze the alerts effectively. In this paper, an approach is proposed to perform alert correlation analysis based on the alert attack path. To handle the raw alerts effectively, the filtering and aggregation methods for big data processing was performed. Alerts were correlated according to the knowledge base and the correlation likelihood. An attack path construction algorithm was performed to obtain the attack paths for a specified victim IP. To present the attacker's strategies visually, an alert correlation graph was constructed to correlate the alerts in a special scope and merged according to the alert types. In addition, we implement the prototype and evaluate the effectiveness and usability of the database provided by an IDS applied in State Grid Corporation of China. The results demonstrate that the approach proposed in this paper improves the efficiency and accuracy in analyzing the attacker's strategies.