Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model
碩士 === 國立嘉義大學 === 資訊工程學系研究所 === 101 === With the Internet and distributed computing technology advancing continuously, Cloud Computing brings more convenience for people and many companies setup their own private cloud because of the characteristics of Cloud Computing. Growing with the technology,...
Main Author: | |
---|---|
Other Authors: | |
Format: | Others |
Language: | zh-TW |
Online Access: | http://ndltd.ncl.edu.tw/handle/62943381943458887035 |
id |
ndltd-TW-101NCYU5392027 |
---|---|
record_format |
oai_dc |
spelling |
ndltd-TW-101NCYU53920272016-03-18T04:41:38Z http://ndltd.ncl.edu.tw/handle/62943381943458887035 Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model 使用貝式網路模型建構可調式特徵權重之警報關聯系統 楊吉閔 碩士 國立嘉義大學 資訊工程學系研究所 101 With the Internet and distributed computing technology advancing continuously, Cloud Computing brings more convenience for people and many companies setup their own private cloud because of the characteristics of Cloud Computing. Growing with the technology, there are many new attack techniques presented in the cloud environment. Different from the general server, once the cloud environment suffered from malicious attacks, people or companies will get caught in extreme dangers. Therefore, it is important for network security in Cloud, and we proposed the Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model to defense the attacks of intruders. There are many network traffic include malicious packets, thus huge amounts of alerts will be generated by the intrusion detection system. Analyzing these alert data is time-consuming and it is difficult to obtain the attack steps and strategies immediately by directly performing these analyses. In recent year, the trend of research in this area is towards alert correlation. We can analysis these alerts and obtain the attack strategies of attacker, and then response and prevent the next step of the attacker intrusion. In this thesis we proposed a new correlation method that employs a Bayesian Network to choose the features with high relevance and then build the Feature Weight Matrix (FWM) and adjusts the feature weights according to the statistics of Bayesian Network in a period of time. According to FWM, we choose the features of two alert types with high relevance to calculate the correlation probabilities. The correlation probability is recorded in the Alert Correlation Matrix (ACM). ACM is updated in each time correlation. Using the information in ACM, we can extract high level attack strategies and build up the attack graphs. The administrator can recognize the attack strategies of attacker and react the attack immediately. We expect for our proposed correlation method can be implemented in the cloud environment. Face the huge number of network traffic, we hope that our proposed method can accurately report the network security situation in real-time. Chih-Hung Wang 王智弘 學位論文 ; thesis 0 zh-TW |
collection |
NDLTD |
language |
zh-TW |
format |
Others
|
sources |
NDLTD |
description |
碩士 === 國立嘉義大學 === 資訊工程學系研究所 === 101 === With the Internet and distributed computing technology advancing continuously, Cloud Computing brings more convenience for people and many companies setup their own private cloud because of the characteristics of Cloud Computing. Growing with the technology, there are many new attack techniques presented in the cloud environment. Different from the general server, once the cloud environment suffered from malicious attacks, people or companies will get caught in extreme dangers. Therefore, it is important for network security in Cloud, and we proposed the Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model to defense the attacks of intruders.
There are many network traffic include malicious packets, thus huge amounts of alerts will be generated by the intrusion detection system. Analyzing these alert data is time-consuming and it is difficult to obtain the attack steps and strategies immediately by directly performing these analyses. In recent year, the trend of research in this area is towards alert correlation. We can analysis these alerts and obtain the attack strategies of attacker, and then response and prevent the next step of the attacker intrusion.
In this thesis we proposed a new correlation method that employs a Bayesian Network to choose the features with high relevance and then build the Feature Weight Matrix (FWM) and adjusts the feature weights according to the statistics of Bayesian Network in a period of time. According to FWM, we choose the features of two alert types with high relevance to calculate the correlation probabilities. The correlation probability is recorded in the Alert Correlation Matrix (ACM). ACM is updated in each time correlation. Using the information in ACM, we can extract high level attack strategies and build up the attack graphs. The administrator can recognize the attack strategies of attacker and react the attack immediately.
We expect for our proposed correlation method can be implemented in the cloud environment. Face the huge number of network traffic, we hope that our proposed method can accurately report the network security situation in real-time.
|
author2 |
Chih-Hung Wang |
author_facet |
Chih-Hung Wang 楊吉閔 |
author |
楊吉閔 |
spellingShingle |
楊吉閔 Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model |
author_sort |
楊吉閔 |
title |
Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model |
title_short |
Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model |
title_full |
Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model |
title_fullStr |
Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model |
title_full_unstemmed |
Adaptive Feature-Weighted Alert Correlation System using Bayesian Network Model |
title_sort |
adaptive feature-weighted alert correlation system using bayesian network model |
url |
http://ndltd.ncl.edu.tw/handle/62943381943458887035 |
work_keys_str_mv |
AT yángjímǐn adaptivefeatureweightedalertcorrelationsystemusingbayesiannetworkmodel AT yángjímǐn shǐyòngbèishìwǎnglùmóxíngjiàngòukědiàoshìtèzhēngquánzhòngzhījǐngbàoguānliánxìtǒng |
_version_ |
1718206834428346368 |