首页    期刊浏览 2024年09月29日 星期日
登录注册

文章基本信息

  • 标题:Correlating Intrusion Alerts into Attack Scenarios based on Improved Evolving Self-Organizing Maps
  • 本地全文:下载
  • 作者:Yun Xiao, Chongzhao Han
  • 期刊名称:International Journal of Computer Science and Network Security
  • 印刷版ISSN:1738-7906
  • 出版年度:2006
  • 卷号:6
  • 期号:6
  • 页码:199-203
  • 出版社:International Journal of Computer Science and Network Security
  • 摘要:Traditional intrusion detection systems (IDSs) focus on low-level attacks and anomalies, and raise alerts independently, though there may be logical connections between them. In this paper, a method of correlating intrusion alerts into attack scenarios based on the improved evolving self-organizing map (IESOM) was proposed. IESOM gives a rational formula to calculate the initial values of connection strengths instead of assigning some experiential or tentative constants as connection strength values in ESOM. IESOM is an evolving extension of the self-organizing map (SOM) model, which allows for an evolvable network structure and very fast incremental learning. System of correlating intrusion alerts into attack scenarios based on IESOM has four functions of filtering, aggregation, condensing and combination, and the visual attack scenarios are given as the output of the system. The results on LLS DDOS1.0 and real-word dataset B prove that our method is useful and effective.
  • 关键词:Intrusion alert, correlation, attack scenarios, improved evolving self-organizing map
国家哲学社会科学文献中心版权所有