基于攻击分类的攻击树生成算法研究

A Study on Detection-Oriented Attack Classification and Attack Tree Generating Algorithm

  • 摘要: 提出一种面向检测的攻击分类方法——DetectClass方法,进行形式化的分析和证明,进而提出相应的攻击树生成算法.DetectClass分类方法的使用,可以提高检测的效率和精度;攻击树生成算法可以自动建立攻击模型,并可以重用攻击模型.经实验验证算法是有效的.

     

    Abstract: A new detection oriented attack classification approach——DetectClass, based on the data collected directly by the intrusion detection system (IDS), is proposed. The DetectClass approach is analyzed and testified using formal techniques. Based on the approach, the corresponding attack tree generating algorithm is presented, and is tested by concrete instances of attack. The results show that the algorithm is effective and efficient. In doing so, the efficiency and accuracy of IDS detection is improved, and the attack patterns can be generated automatically and reused applying the attack tree generating algorithm.

     

/

返回文章
返回
Baidu
map