• DocumentCode
    3580257
  • Title

    Automatic generation of correlation rules to detect complex attack scenarios

  • Author

    Godefroy, Erwan ; Totel, Eric ; Hurfin, Michel ; Majorczyk, Frederic

  • Author_Institution
    DGA-MI, Bruz, France
  • fYear
    2014
  • Firstpage
    23
  • Lastpage
    28
  • Abstract
    In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.
  • Keywords
    security of data; action tree; alert correlation systems; attack description language; automatic correlation rule generation; complex attack scenarios; complex multistep attack identification; distributed information systems; elementary security alerts; exhaustive correlation rules; fully automated transformation process; Monitoring; Intrusion detection; Security and Protection;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Assurance and Security (IAS), 2014 10th International Conference on
  • Print_ISBN
    978-1-4799-8098-7
  • Type

    conf

  • DOI
    10.1109/ISIAS.2014.7064615
  • Filename
    7064615