Graph-Based Real-Time Security Threats Awareness and Analysis in Enterprise LAN

  • Lv H
  • Zhang Y
  • Wang R
  • et al.
N/ACitations
Citations of this article
2Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In order to dynamically and accurately recognize real-time networksecurity situation in an enterprise LAN, an awareness and analysismethod for network threats is proposed. The method recognizes currentreal-time threats and predicts subsequent threats by modeling attackscenario and simulating intrusion state transferring. The threatawareness model is constructed with Expanded Finite-State Automata,which is defined as Attack State Transition Graph and Real-Time AttackState Graph. The former visually describes all possible intruding pathsand state transitions, and the latter illustrates really happeningthreats and real-time state transition. Then threat awareness algorithmis presented, of which various kinds of invalid threats are filtered,and current valid threats are obtained by correlating dynamic alarmswith static attack scenario. Further, combining ASTG with RASG,subsequent threat and possible threat path is identified, which providesa useful evidence and guidance for intrusion response and securitydecision. Finally the results of experiment in a simulated networkverify validity of the method.

Cite

CITATION STYLE

APA

Lv, H., Zhang, Y., Wang, R., & Wang, J. (2015). Graph-Based Real-Time Security Threats Awareness and Analysis in Enterprise LAN. In LISS 2013 (pp. 1299–1304). Springer Berlin Heidelberg. https://doi.org/10.1007/978-3-642-40660-7_195

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free