Multistep attack detection and alert correlation in intrusion detection systems

22Citations
Citations of this article
35Readers
Mendeley users who have this article in their library.
Get full text

Abstract

A growing trend in the cybersecurity landscape is represented by multistep attacks that involve multiple correlated intrusion activities to reach the intended target. The duty of reconstructing complete attack scenarios is left to system administrators because current Network Intrusion Detection Systems (NIDS) are still oriented to generate alerts related to single attacks, with no or minimal correlation. We propose a novel approach for the automatic analysis of multiple security alerts generated by state-of-the-art signature-based NIDS. Our proposal is able to group security alerts that are likely to belong to the same attack scenario, and to identify correlations and causal relationships among them. This goal is achieved by combining alert classification through Self Organizing Maps and unsupervised clustering algorithms. The efficacy of the proposal is demonstrated through a prototype tested against network traffic traces containing multistep attacks. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Manganiello, F., Marchetti, M., & Colajanni, M. (2011). Multistep attack detection and alert correlation in intrusion detection systems. In Communications in Computer and Information Science (Vol. 200 CCIS, pp. 101–110). https://doi.org/10.1007/978-3-642-23141-4_10

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free