Title
Real-Time Correlation of Network Security Alerts
Abstract
With the growing deployment of network security devices, it becomes a great challenge to manage the large volume of security alerts from these devices. In this paper a novel method using sequential pattern mining algorithm is applied to discover complicated multistage attack behavior patterns. Their result can be transformed into rules automatically. In contrast with other approaches, it overcomes the drawback of high dependence on precise attack specifications and accurate rule definitions. Based on the algorithms, a real-time alert correlation system is proposed to detect an ongoing attack and predict the upcoming next step of a multistage attack in real time. Consequently, network administrator can be aware of the threat as soon as possible and take deliberate action to prevent the target of an attack from further compromise. We implement the system and valid our method by a series of experiments with test dataset and in real network environment. The result shows the effectivity of the system in discovery and predication of attacks.
Year
DOI
Venue
2007
10.1109/ICEBE.2007.89
ICEBE
Keywords
Field
DocType
data mining,sequential pattern mining,real time,network security
Drawback,Data mining,Software deployment,Computer science,Network security,Correlation,Network administrator,Security information and event management,Network Access Control,Computer security model
Conference
Volume
Issue
ISBN
null
null
0-7695-3003-6
Citations 
PageRank 
References 
16
0.83
15
Authors
4
Name
Order
Citations
PageRank
Zhitang Li122631.89
Aifang Zhang2292.09
Jie Lei3160.83
Wang Li48215.78