An intrusion alarm data association analysis method
Xiaoling Tao, Fei Jia, Yue-lin Yu, De-xuan Ding, Zi-shuo Cui, Lan Shi · 2022 IEEE 19th International Conference on Mobile Ad Hoc and Smart Systems (MASS) · 2022
Network security is currently facing severe chal-lenges. Intrusion Detection System (IDS) can detect the Intrusion behavior of the network environment. In practical applications, IDS will produce a large number of redundant and false alarms, and these low-level alarm data cannot show the whole picture of the attack. This makes it impossible for Network administrator to identify an intruder's attack strategy based on the complete attack process. Aiming at the above problems, In this paper, we first use the clustering algorithm to fuse the redundant alarm data, and then proposes an alarm data association analysis method based on the attack scenario. This method uses the mechanism of dynamic time window to divide the attack scenario, and then uses two complementary methods based on causality and GCT to analyze the alarm data, finally construct the attack scenario. The experimental results show that this method can effectively prevent redundant alarm data, reduce the false-positive rate of an IDS, improve the association efficiency, and restore a relatively complete attack process.