摘要
入侵检测系统仅能检测到攻击,但不能预测攻击者下一步的攻击。分析了基于攻击行为预测方法的不足,提出了一种基于攻击意图的复合攻击预测方法。该方法使用抽象的攻击意图表示复合攻击,采用扩展的有向图表达攻击意图间的逻辑关系,建立了攻击匹配的攻击意图框架,在复合攻击预测算法中引入了攻击检测度和攻击匹配度两个概念。最后,通过实验验证了该方法的有效性。
Attack can be only detected, but the attacker's next attack can't be forecasted by intrusion detection system. The default of the approach to forecasting attack based on attack behavior is analyzed, a forecast algorithm for multi-step attack based on attack intention is addressed. Multi-step attack is modeled by attack intention and the logic relationship between attack intention is expressed by extended directed graph. The attack intention frame of attack for attack to match is addressed. The degree of detected attack and matched attack is defined. At the end, the validity of the algorithm is proved by the experimental results.
出处
《计算机工程与设计》
CSCD
北大核心
2007年第21期5100-5102,共3页
Computer Engineering and Design
关键词
攻击
复合攻击
攻击意图
攻击预测
攻击意图逻辑关系图
attack
multi-step attack
attack intention
forecast attack
logic graph of attack intention