• DocumentCode
    1626475
  • Title

    Automatic learning of attack behavior patterns using Bayesian networks

  • Author

    Kavousi, F. ; Akbari, Behzad

  • Author_Institution
    Fac. of Electr. & Comput. Eng., Tarbiat Modares Univ., Tehran, Iran
  • fYear
    2012
  • Firstpage
    999
  • Lastpage
    1004
  • Abstract
    A tremendous number of low-level alerts reported by information security systems makes it challenging for security administrators to do an effective analysis and initiate a timely response. Alert correlation techniques have been proposed to reduce the number of alerts and provide a succinct and high-level view of attacks. Most of the existing approaches rely on a priori and hard-coded domain knowledge that leads to their difficult implementation and limited capabilities of detecting new attack strategies. To address the drawbacks of these approaches, the recent trend of research in this area has gone towards extracting attack strategies through automatic analysis of intrusion alerts. In this paper, we present new algorithms to mine attack behavior patterns from a large number of intrusion alerts without specific prior knowledge about attacks. Unlike expert knowledge-based methods, our proposed scheme automatically generates correlation rules from the previously observed alerts using a Bayesian causality mechanism. The attack activity patterns learned by this way can help us to correlate alerts, reconstruct attack scenarios and predict possible forthcoming attacks in a real-time system. Our experimental results clearly show efficiency of the proposed method in learning new attack strategies.
  • Keywords
    belief networks; computer network security; correlation theory; learning (artificial intelligence); Bayesian causality mechanism; Bayesian network; attack behavior pattern detection; automatic learning; correlation technique; expert knowledge-based method; hard-coded domain knowledge; information security system; intrusion detection; security administrator; Bayes methods; Correlation; History; IP networks; Ports (Computers); Security; Vectors; Alert Correlation; Bayesian Network; Intrusion Detection; Network Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Telecommunications (IST), 2012 Sixth International Symposium on
  • Conference_Location
    Tehran
  • Print_ISBN
    978-1-4673-2072-6
  • Type

    conf

  • DOI
    10.1109/ISTEL.2012.6483132
  • Filename
    6483132