TY - GEN
T1 - Automatic generation of correlation rules to detect complex attack scenarios
AU - Godefroy, Erwan
AU - Totel, Eric
AU - Hurfin, Michel
AU - Majorczyk, Frederic
N1 - Publisher Copyright:
© 2014 IEEE.
PY - 2014/3/19
Y1 - 2014/3/19
N2 - In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.
AB - In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.
KW - Intrusion detection
KW - Security and Protection
U2 - 10.1109/ISIAS.2014.7064615
DO - 10.1109/ISIAS.2014.7064615
M3 - Conference contribution
AN - SCOPUS:84946693594
T3 - 2014 10th International Conference on Information Assurance and Security, IAS 2014
SP - 23
EP - 28
BT - 2014 10th International Conference on Information Assurance and Security, IAS 2014
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 2014 10th International Conference on Information Assurance and Security, IAS 2014
Y2 - 28 November 2014 through 30 November 2014
ER -