课题基金 / 基金详情

Reduce False Alerts, Uncover High-Level Attack Strategies and Predict Attacks in Progress Using Prerequisites of Intrusions

Reduce False Alerts, Uncover High-Level Attack Strategies and Predict Attacks in Progress Using Prerequisites of Intrusions
使用入侵先决条件减少误报、发现高级攻击策略并预测正在进行的攻击
批准号:
0207297
负责人:
Peng Ning
金额:
$33.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-07-01 至 2006-06-30

项目摘要

项目成果

Peng Ning的其他基金

相似基金

相关文献

中文摘要
翻译
目前的入侵检测系统(IDS)通常会产生许多错误的警报,往往不能检测到新的攻击或已知攻击的变化。此外,大多数现有的IDS都集中在低级别的攻击或异常;没有捕获这些攻击背后的逻辑步骤或策略。在有密集入侵的情况下,不仅实际警报会与虚假警报混合,而且警报的数量也会变得无法管理。因此,人类用户或入侵响应系统很难理解攻击的性质并采取适当的行动。为了解决这些问题,本项目将研究基于攻击的先决条件和后果关联入侵警报的技术。该研究使用了一个正式的和严谨的方法来研究涉及警报相关性的基本问题,包括表示的先决条件和后果的攻击,有效的算法来处理警报,表达的高层次的表示机制,有效性的技术,减少虚假警报,影响ofalse警报和未检测到的攻击的技术,以及方法来预测攻击的进展。该研究的预期影响包括:(1)减少错误警报的数量,(2)识别攻击者的高级策略,以及(3)早期配置针对正在进行的攻击的有效防御。如果成功,这项研究将导致更好的入侵检测工具,从而提高计算机和网络安全。
英文摘要
Current intrusion detection systems (IDSs) usually generate many false alerts and often do not detect novel attacks or variations of known attacks. Moreover, most existing IDSs focus on low-level attacks oranomalies; none capture the logical steps or strategies behind these attacks. In situations where there are intensive intrusions, not only will actual alerts be mixed with false alerts, but the number ofalerts will also become unmanageable. As a result, it is difficult for human users or intrusion response systems to understand the nature of the attack and to take appropriate actions.To address these issues, this project will investigate techniques to correlate intrusion alerts on the basis of the prerequisites and consequences of attacks. The research uses a formal and rigorousapproach to study the fundamental issues involved in alert correlation, including representation of prerequisites and consequences of attacks, efficient algorithms to process alerts, expressiveness of the high-level representation mechanisms, effectiveness of the technique in reducing false alerts, impact offalse alerts and undetected attacks on the technique, and methods to predict attacks in progress. Expected impacts of the proposed research include (1) a reduction in the number of false alerts, (2) identification of attackers' high-level strategies, and (3) early configuration of effective defenses against attacks in progress. If successful, the research will lead to better tools for intrusiondetection and thus to improved computer and network security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TC: Large: Collaborative Research: Trustworthy Virtual Cloud Computing
  • 批准号:
    0910767
  • 项目类别:
    Standard Grant
  • 资助金额:
    $152.37万
  • 财政年份:
    2009
  • 负责人:
    Peng Ning
  • 依托单位:
CT-M: Collaborative Research: A Resilient Real-Time System for a Secure and Reconfigurable Power Grid
  • 批准号:
    0831302
  • 项目类别:
    Standard Grant
  • 资助金额:
    $5.0万
  • 财政年份:
    2008
  • 负责人:
    Peng Ning
  • 依托单位:
Collaborative Research: CT-T: A Resilient Real-Time System for a Secure and Reconfigurable Power Grid
  • 批准号:
    0716435
  • 项目类别:
    Standard Grant
  • 资助金额:
    $2.85万
  • 财政年份:
    2007
  • 负责人:
    Peng Ning
  • 依托单位:
NeTS-NOSS: Secure, Robust and DoS-Resilient Code Dissemination in Wireless Sensor Networks
  • 批准号:
    0721424
  • 项目类别:
    Standard Grant
  • 资助金额:
    $26.99万
  • 财政年份:
    2007
  • 负责人:
    Peng Ning
  • 依托单位:
海外基金