引用本文:伏晓,石进,谢立.用于自动证据分析的层次化入侵场景重构方法.软件学报,2011,22(5):996-1008
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 5849次   下载 7137 本文二维码信息
码上扫一扫!
分享到: 微信 更多
用于自动证据分析的层次化入侵场景重构方法
伏晓1, 石进1,2, 谢立1
1.计算机软件新技术国家重点实验室(南京大学),江苏 南京 210093;2.南京大学 国家保密学院,江苏 南京 210093
摘要:
为了能够自动分析入侵证据,提出了一种层次化入侵场景重构方法.其原理是:首先,基于报警关联技术重构出入侵者的抽象攻击步骤及步骤间关系;然后,基于攻击特征和依赖追踪技术重构出各步骤的行为细节;最后,通过两层重构结果的彼此映射,调整获得完整的入侵行为图.基于DARPA 2000 的实验结果表明,该方法的重构结果准确性和完备性均比较高,而且抽象与细节相结合的表示方法更易理解,也更适合作为法律证据.而与现有方法相比,该方法在重构场景的完整性、适用行为的复杂性以及方法安全性等方面也有一定的改善.
关键词:  入侵取证  证据分析  场景重构  依赖追踪  报警关联
DOI:10.3724/SP.J.1001.2011.03759
分类号:
基金项目:江苏省自然科学基金(Bk2009465)
Layered Intrusion Scenario Reconstruction Method for Automated Evidence Analysis
FU Xiao1, SHI Jin1,2, XIE Li1
1.State Key Laboratory for Novel Software Technology (Nanjing University), Nanjing 210093, China;2.School of National Information Security, Nanjing University, Nanjing 210093, China
Abstract:
In order to analyze intrusion evidences automatically, a layered method for reconstructing intrusion scenario is proposed. It includes 3 main phrases. First, the intruder’s abstract steps and the relationships between them are reconstructed by the alert correlation. Secondly, detailed behaviors of each step are reconstructed based on attack signatures and the OS-Level dependency tracking. Finally, the results are mapped and refined, and a behavior graph is generated. This graph can describe the completed intrusion process. The experiments on DARPA 2000 prove that the results are not only easy to understand, but are also full and accurate. Hence, it is fit to be presented in the court. Compared with current methods, this method shows more advantages. For example, it can process more complex scenarios.
Key words:  intrusion forensic  evidence analysis  scenario reconstruction  dependency tracking  alert correlation

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: