Passer à la navigation principale Passer à la recherche Passer au contenu principal

Automatic generation of correlation rules to detect complex attack scenarios

  • Erwan Godefroy
  • , Eric Totel
  • , Michel Hurfin
  • , Frederic Majorczyk
  • DGA-MI
  • Supelec
  • INRIA Institut National de Recherche en Informatique et en Automatique

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

Résumé

In large distributed information systems, alert correlation systems are necessary to handle the huge amount of elementary security alerts and to identify complex multi-step attacks within the flow of low level events and alerts. In this paper, we show that, once a human expert has provided an action tree derived from an attack tree, a fully automated transformation process can generate exhaustive correlation rules that would be tedious and error prone to enumerate by hand. The transformation relies on a detailed description of various aspects of the real execution environment (topology of the system, deployed services, etc.). Consequently, the generated correlation rules are tightly linked to the characteristics of the monitored information system. The proposed transformation process has been implemented in a prototype that generates correlation rules expressed in an attack description language.

langue originaleAnglais
titre2014 10th International Conference on Information Assurance and Security, IAS 2014
EditeurInstitute of Electrical and Electronics Engineers Inc.
Pages23-28
Nombre de pages6
ISBN (Electronique)9781479980994
Les DOIs
étatPublié - 19 mars 2014
Modification externeOui
Evénement2014 10th International Conference on Information Assurance and Security, IAS 2014 - Okinawa, Japon
Durée: 28 nov. 201430 nov. 2014

Série de publications

Nom2014 10th International Conference on Information Assurance and Security, IAS 2014

Une conférence

Une conférence2014 10th International Conference on Information Assurance and Security, IAS 2014
Pays/TerritoireJapon
La villeOkinawa
période28/11/1430/11/14

Empreinte digitale

Examiner les sujets de recherche de « Automatic generation of correlation rules to detect complex attack scenarios ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation