| 摘要: |
| 为了能够自动分析入侵证据,提出了一种层次化入侵场景重构方法.其原理是:首先,基于报警关联技术重构出入侵者的抽象攻击步骤及步骤间关系;然后,基于攻击特征和依赖追踪技术重构出各步骤的行为细节;最后,通过两层重构结果的彼此映射,调整获得完整的入侵行为图.基于DARPA 2000 的实验结果表明,该方法的重构结果准确性和完备性均比较高,而且抽象与细节相结合的表示方法更易理解,也更适合作为法律证据.而与现有方法相比,该方法在重构场景的完整性、适用行为的复杂性以及方法安全性等方面也有一定的改善. |
| 关键词: 入侵取证 证据分析 场景重构 依赖追踪 报警关联 |
| DOI:10.3724/SP.J.1001.2011.03759 |
| 分类号: |
| 基金项目:江苏省自然科学基金(Bk2009465) |
|
| Layered Intrusion Scenario Reconstruction Method for Automated Evidence Analysis |
|
FU Xiao1, SHI Jin1,2, XIE Li1
|
|
1.State Key Laboratory for Novel Software Technology (Nanjing University), Nanjing 210093, China;2.School of National Information Security, Nanjing University, Nanjing 210093, China
|
| Abstract: |
| In order to analyze intrusion evidences automatically, a layered method for reconstructing intrusion scenario is proposed. It includes 3 main phrases. First, the intruder’s abstract steps and the relationships between them are reconstructed by the alert correlation. Secondly, detailed behaviors of each step are reconstructed based on attack signatures and the OS-Level dependency tracking. Finally, the results are mapped and refined, and a behavior graph is generated. This graph can describe the completed intrusion process. The experiments on DARPA 2000 prove that the results are not only easy to understand, but are also full and accurate. Hence, it is fit to be presented in the court. Compared with current methods, this method shows more advantages. For example, it can process more complex scenarios. |
| Key words: intrusion forensic evidence analysis scenario reconstruction dependency tracking alert correlation |