现有攻击行为分析技术大致可以分为"面向网络"和"面向攻击者"两类。与传统的"面向网络"的分析方法相比,"面向攻击者"的分析方法更多地考虑了主体相关性等因素,因此分析结果更为准确、可靠。基于以往在攻击行为分析技术领域的相关研究成果,设计并实现了一种面向攻击者的入侵告警分析原型系统CABAS。基于Darpa2000数据集的离线测试结果表明,该系统能够实现对多方合作的复杂攻击进行准确分析,大大提高安全管理工作的有效性。
Cyber attack behavior analysis techniques can be roughly classified as network-oriented analysis and attacker-oriented analysis.Compared with traditional network-oriented attack behavior analysis,attacker-oriented attack behavior analysis takes account of the relationship among attackers,so that it can present more accurate and more reliable performance.Based on the attack behavior analysis techniques that the authors have presented before,the design and implementation of an attacker-oriented intrusion alert analysis prototype system CABAS is presented.The system is evaluated under Darpa2000 intrusion detection evaluation datasets,the experimental results show that this approach has potential in analyzing complex cooperative attacks and improving the effectiveness and efficiency of security management.