Recognizing multistage cyber attacks via CPN approach

Yi Ming Chen, Hsing Kuo Wong, Mei Chun Liu

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

As the rapid growth of Internet applications, the number of cyber attacks increases drastically and presents challenges to network administrators. One of the challenges comes from that Internet hackers usually take multiple actions to achieve their malicious objectives; thus blurred their intention by triggering several seeming unrelated alerts during the same attack scenario. As a result, either for earning enough time to take appropriate actions or for reducing the number of alerts by correlating them, the administrators naturally want to have a quick way to recognize the multistage attacks. To address this desire, this paper presents a novel Colored Petri Net (CPN) based approach for administrators to correlate the alerts caused by intrusion detection systems to identify whether a multistage attack occurs or not. With this approach, we developed a CPN model to represent cyber attacks, and also implemented a prototype system to validate the effectiveness of our approach. We took DARPA/Lincoln Laboratory 2000 datasets as experiment inputs; the results showed that the CPN approach could recognize the multistage attacks, such as sadmind attack, from these alert datasets while has simpler modeling representation as well as friendlier user interface than alternative approaches.

Original languageEnglish
Title of host publicationWMSCI 2005 - The 9th World Multi-Conference on Systemics, Cybernetics and Informatics, Proceedings
Pages1-6
Number of pages6
StatePublished - 2005
Event9th World Multi-Conference on Systemics, Cybernetics and Informatics, WMSCI 2005 - Orlando, FL, United States
Duration: 10 Jul 200513 Jul 2005

Publication series

NameWMSCI 2005 - The 9th World Multi-Conference on Systemics, Cybernetics and Informatics, Proceedings
Volume5

Conference

Conference9th World Multi-Conference on Systemics, Cybernetics and Informatics, WMSCI 2005
Country/TerritoryUnited States
CityOrlando, FL
Period10/07/0513/07/05

Keywords

  • Alert correlation
  • Attack modeling
  • Colored Petri Net
  • Multistage attacks

Fingerprint

Dive into the research topics of 'Recognizing multistage cyber attacks via CPN approach'. Together they form a unique fingerprint.

Cite this