首页|基于概率攻击图的内部攻击意图推断算法研究

基于概率攻击图的内部攻击意图推断算法研究

扫码查看
内部攻击行为具有明显的多步骤性和伪装性.这些特性增加内部攻击检测的难度,影响检测结果的准确性.攻击图模型能够描述攻击行为的多个攻击步骤之间的因果关系,但由于单步攻击检测结果存在的不确定性,使得攻击图模型无法准确地推断攻击者的意图.该文在攻击图模型中引入转移概率表,刻画单步攻击检测结果的不确定性,即从观测事件推导出某步攻击发生的概率,提出了一个面向内部攻击意图推断的概率攻击图模型.基于该模型,提出了一种推断内部攻击意图的算法以及针对攻击目标的最大概率攻击路径的计算方法.实验结果表明该文的工作能够有效地推断攻击意图和计算攻击路径,减少不可信报警数量,为网络安全管理员提供良好的可配置性.
Inferring Attack Intent of Malicious Insider Based on Probabilistic Attack Graph Model
Attacks from malicious insiders usually consist of multiple attacking steps and disguise themselves as normal behaviors,which increase the difficulty to detect them and decrease the accuracy of detection results.Although attack graph model can describe the causal relationships among the steps in one attack progress,it cannot accurately infer the attacker's intent,because of the uncertainty of the detection results for each step.This paper introduces a transition probability table to depict this uncertainty,namely the occurrence probability of one attack step obtained from observed events,and propose a probabilistic attack graph model for inferring the intents of inside attacks.Based on the model,we further propose an algorithm to infer the intents under given sequences of observed events,and a method to calculate the attack path with the highest probability for a given attack target.Experimental results show that our work can dramatically reduce the number of alarms for inside attacks,so as to effectively infer intents,and provide good configurability for the network security administrators.

insider attackprobabilistic attack graphbehavioral analysisintent inferringnetwork behavior

陈小军、方滨兴、谭庆丰、张浩亮

展开 >

中国科学院计算技术研究所 北京 100190

中国科学院信息工程研究所信息内容安全技术国家工程实验室 北京100093

中国科学院大学信息科学与工程学院 北京 100049

国科学院计算技术研究所 北京 100190

展开 >

内部攻击 概率攻击图 行为分析 意图推断 网络行为

本课题得到国家“八六三”高技术研究发展计划项目中国科学院战略性先导科技专项课题

2012AA013101XDA06030200

2014

计算机学报
中国计算机学会 中国科学院计算技术研究所

计算机学报

CSTPCDCSCD北大核心EI
影响因子:3.18
ISSN:0254-4164
年,卷(期):2014.37(1)
  • 74
  • 2