为提高告警因果关联准确性,提出了将实施单次攻击所需的时间消耗作为随机变量,给出其概率分布模型,在此基础上计算任意2条因果相关告警的时间关联置信度。设计并实现了算法验证程序,利用DARPA 2000入侵检测数据集进行了验证。结果表明,新方法合理地量化了告警时间关联置信度,且计算复杂度低,能为正确关联攻击场景提供支持。
In order to improve the precision of alert correlation,a network security alert correlation method based on the attack time consumption model was proposed. The attack time consumption was taken as a random variable and its probabilistic distribution was defined. Based on the distribution, the temporal correlation belief metric of any two alerts which might have potential causal relationship could be calculated. To testify the feasibility, a prototype system was designed, implemented and tested with the DARPA 2000 IDS evaluation dataset. Result shows that the method can reasonably evaluate the temporal correlation belief of the causal related alerts and provide a complementary support for the attack scenario construction.