• DocumentCode
    3156879
  • Title

    Using Network Attack Graph to Predict the Future Attacks

  • Author

    Lei, Jie ; Li, Zhi-Tang

  • Author_Institution
    Huazhong Univ. of Sci. & Technol., Wuhan
  • fYear
    2007
  • fDate
    22-24 Aug. 2007
  • Firstpage
    403
  • Lastpage
    407
  • Abstract
    An intrusion detection system (IDS) generates alerts indicating what malicious behaviors are going on against the protected network system. When comparing the real-time reported IDS alerts with the network attack graph which provides all possible sequences of exploits that an intruder may use to penetrate the system, some prediction on future attacks can be made. In this paper we proposed a novel approach to predicting future attacks. First an attack graph is generated through data mining and the predictability of every attack scenario which represents how probable there would be oncoming attacks following the attack scenario can be estimated. Then in real-time intrusion detection environment the IDS alerts are correlated into attack scenarios and ranked by their predictability scores. Finally the attack scenarios with high predictability are used as the evidence to make prediction on future attacks. The effectiveness of the approach has been validated with a honeynet system.
  • Keywords
    data mining; graph theory; security of data; attack scenario; data mining; honeynet system; network attack graph; network system protection; real-time intrusion detection; Computer science; Data security; Forensics; Inference mechanisms; Intrusion detection; Libraries; Protection; Real time systems; Testing; Tree graphs;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Communications and Networking in China, 2007. CHINACOM '07. Second International Conference on
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-1-4244-1009-5
  • Electronic_ISBN
    978-1-4244-1009-5
  • Type

    conf

  • DOI
    10.1109/CHINACOM.2007.4469413
  • Filename
    4469413