期刊导航

论文摘要

基于WOWA-FCM的复合攻击检测模型

A Detection Model for Multi-stage Attacks Based on WOWA-FCM

作者:吕镇邦(西安电子科技大学 计算机网络与信息安全教育部重点实验室,陕西 西安 710071);周利华(西安电子科技大学 计算机网络与信息安全教育部重点实验室,陕西 西安 710071)

Author:(Key Lab. for Computer Networks and Info. Security of Ministry of Edu., Xidian Univ., Xi’an 710071, China);(Key Lab. for Computer Networks and Info. Security of Ministry of Edu., Xidian Univ., Xi’an 710071, China)

收稿日期:2006-09-23          年卷(期)页码:2008,40(1):122-126

期刊名称:工程科学与技术

Journal Name:Advanced Engineering Sciences

关键字:复合攻击;模糊认知图;入侵检测;WOWA算子;警报关联

Key words:multi-stage attack; Fuzzy Cognitive Maps(FCM); intrusion detection; Weighted Ordered Weighted Averaging operator(WOWA); alert correlation

基金项目:国家自然科学基金资助项目(60573036); 航空基础科学基金资助项目(03F31007)

中文摘要

为有效处理复合攻击检测中的诸多不确定性及复杂性因素,提出了基于WOWA-FCM的复合攻击检测模型。WOWA-FCM检测模型从攻击意图分析的角度,利用模糊认知图(Fuzzy Cognitive Maps, FCM)对初级入侵警报进行因果关联;并结合脆弱性知识与系统配置信息,利用WOWA(Weighted Ordered Weighted Averaging)算子融合关联数据。WOWA-FCM检测模型不仅能识别复合攻击各个阶段、构建完整的攻击视图,并且能动态地评判攻击进度和目标系统的安全状态。WOWA-FCM

英文摘要

In order to handle the uncertainties and complexities of multi-stage attack detection effectively, a novel detection model for multi-stage attacks based on Weighted Ordered Weighted Averaging (WOWA) and Fuzzy Cognitive Maps (FCM) was proposed. Based on Attack Intention Analysis, the WOWA-FCM detection model implemented the Cause Effect correlation of the primary intrusion alerts along with the vulnerability and configuration information of the target system utilizing Fuzzy Cognitive Maps, and implemented the effects fusion via WOWA aggregation operators. The WOWA-FCM approach was not only able to recognize the individual stages of a multi stage attack, construct the whole attack scenario, but also able to evaluate the global attack process and the security states of the target system dynamically. The WOWA-FCM model simplified the conventional multi-stage attack detection process, and provided with a better adaptability. The effectiveness of this approach was verified by the Mstream DDoS detection experimental results.

关闭

Copyright © 2020四川大学期刊社 版权所有.

地址:成都市一环路南一段24号

邮编:610065