• DocumentCode
    2625045
  • Title

    Semantic scheme to extract attack strategies for Web service network security

  • Author

    Yan, Wei ; Liu, Fang

  • Author_Institution
    Dept. of Electr. & Comput. Eng., New Jersey Inst. of Technol., Newark, NJ, USA
  • fYear
    2004
  • fDate
    11-13 Oct. 2004
  • Firstpage
    104
  • Lastpage
    111
  • Abstract
    In the recent years, Web technologies have been used to provide an interface to the distributed services. The advent of the computer networks has accelerated this development, and has sparked the emergence of the numerous environments that enable Web services. However, the computer network security against the distributed denial of service attacks (DDoS) attacks attracts more attentions. The overwhelming alerts generated by the intrusion detection systems make it hard for the security administrator to analyze and extract the attack strategies, which hampers the performance of the attack detection. One method to resolve the problem is the attack scenarios extraction. In this paper, we propose a novel way to correlate the alerts and extract the attack scenarios. The modified case grammar, principal-subordinate consequence tagging case grammar and the alert semantic network, are used to generate the attack classes. Alerts mutual information is also applied to calculate the alert semantic context window size. Afterwards, based on the alert context, the attack instances are extracted.
  • Keywords
    Internet; security of data; semantic networks; Web service network security; alert semantic context window size; attack strategy extraction; computer network security; distributed denial of service attacks; distributed services; intrusion detection systems; modified case grammar; principal-subordinate consequence tagging case grammar; security administrator; semantic scheme; Acceleration; Computer crime; Computer networks; Computer security; Data mining; Intrusion detection; Mutual information; Performance analysis; Tagging; Web services; alerts correlation; intrusion detection; mutual information; network security; web services;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    IP Operations and Management, 2004. Proceedings IEEE Workshop on
  • Print_ISBN
    0-7803-8836-4
  • Type

    conf

  • DOI
    10.1109/IPOM.2004.1547600
  • Filename
    1547600