DocumentCode :
3214888
Title :
Assessing Attack Threat by the Probability of Following Attacks
Author :
Li, Zhi-Tang ; Lei, Jie ; Wang, Li ; Li, Dong
Author_Institution :
Dept. of Comput. Sci., Huazhong Univ. of Sci. & Technol., Wuhan
fYear :
2007
fDate :
29-31 July 2007
Firstpage :
91
Lastpage :
100
Abstract :
In this paper a novel approach to assessing the threat of network intrusions is proposed. Unlike the present approaches which assess the attack threat either from a backward perspective (how probable a security state can be reached) or from the perspective of the attacks themselves (how much an attack would cause damage to the network), this approach assesses the attack threat from a forwarding perspective (how probable it would be the precursor of future attacks). First, to every attack type and some attack scenarios, their probabilities of having following attacks(PFAs) are calculated by a data mining algorithm. Then the threats of real time intrusions are assessed by these probabilities. The result of the threat assessment can help identify the intrusion alerts which would be the best evidence for the coming attacks from tremendous amount of intrusion alerts, thus this approach can be used for intrusion prediction. The approach is validated by DARPA 2000 and DARPA 1999 intrusion detection evaluation datasets.
Keywords :
data mining; security of data; attack threat assessment; data mining algorithm; intrusion detection; Computer science; Data mining; Data security; Floods; Frequency; Intrusion detection; Monitoring; Network topology; Probability; Secure storage;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Networking, Architecture, and Storage, 2007. NAS 2007. International Conference on
Conference_Location :
Guilin
Print_ISBN :
0-7695-2927-5
Type :
conf
DOI :
10.1109/NAS.2007.15
Filename :
4286413
Link To Document :
بازگشت