Passer à la navigation principale Passer à la recherche Passer au contenu principal

Generation and assessment of correlation rules to detect complex attack scenarios

  • Erwan Godefroy
  • , Eric Totel
  • , Michel Hurfin
  • , Frederic Majorczyk
  • DGA-MI
  • Supelec
  • INRIA Institut National de Recherche en Informatique et en Automatique

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionContribution à une conférenceRevue par des pairs

2 Citations (Scopus)

Résumé

Information systems can be targeted by different types of attacks. Some of them are easily detected (like an DDOS targeting the system) while others are more stealthy and consist in successive attacks steps that compromise different parts of the targeted system. The alarm referring to detected attack steps are often hidden in a tremendous amount of notifications that include false alarms. Alert correlators use correlation rules (that can be explicit, implicit or semi-explicit [3]) in order to solve this problem by extracting complex relationships between the different generated events and alerts. On the other hand, providing maintainable, complete and accurate correlation rules specifically adapted to an information system is a very difficult work. We propose an approach that, given proper input information, can build a complete and system dependant set of correlation rules derived from a high level attack scenario. We then evaluate the applicability of this method by applying it to a real system and assessing the fault tolerance in a simulated environment in a second phase.

langue originaleAnglais
titre2015 IEEE Conference on Communications and NetworkSecurity, CNS 2015
EditeurInstitute of Electrical and Electronics Engineers Inc.
Pages707-708
Nombre de pages2
ISBN (Electronique)9781467378765
Les DOIs
étatPublié - 3 déc. 2015
Modification externeOui
Evénement3rd IEEE International Conference on Communications and Network Security, CNS 2015 - Florence, Italie
Durée: 28 sept. 201530 sept. 2015

Série de publications

Nom2015 IEEE Conference on Communications and NetworkSecurity, CNS 2015

Une conférence

Une conférence3rd IEEE International Conference on Communications and Network Security, CNS 2015
Pays/TerritoireItalie
La villeFlorence
période28/09/1530/09/15

Empreinte digitale

Examiner les sujets de recherche de « Generation and assessment of correlation rules to detect complex attack scenarios ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation