透過您的圖書館登入
IP:3.144.113.197

並列摘要


Current techniques employed in security alert correlation area for multi-step attack recognition purpose are intricate to be performed due to the complexity of the methods and huge computing workload generated during alert analysis and processing. In this paper, we proposed a new method of alert correlation aiming at providing concentrated security event information and thus finding multi-step attack patterns accordingly. We use a kind of extension time window when aggregate the alerts into high level alerts. We then connect hyper alerts into candidate multi-step attack patterns according to their IP address association. The final real multi-step attack patterns are discovered from these connected attack patterns with quantitative correlation calculation method. The method is easy to implement and practical to deploy which is proved by the result of our experiments. The experiment also shows our approach can effectively find real multi-step attack behavior patterns and can be used to identify true attack threats.

被引用紀錄


孫君寧(2017)。玉山國家公園高海拔山區土壤中低溫細菌多樣性之研究〔碩士論文,國立臺灣大學〕。華藝線上圖書館。https://doi.org/10.6342/NTU201703004
雍華恩(2014)。氧化銫鎢滴附石墨烯的光偵測器元件光電特性研究〔碩士論文,國立中正大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613592494
吳佳穎(2014)。氧化鎢/二氧化鈦之合成及其抗腐蝕 與光催化之應用〔碩士論文,國立中央大學〕。華藝線上圖書館。https://www.airitilibrary.com/Article/Detail?DocID=U0031-0412201511585621

延伸閱讀