An Approach for Attack Scenario Construction Based on Dynamic Attack Path Graph

  • Siying He
  • , Mi Wen
  • , Xiumin Li
  • , Zhou Su

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

With the complexity and variability of cyber attacks increasing, current approaches for constructing attack scenarios often overlook the continuity of attack behaviors. These approaches lead to challenges in dynamically reconstructing the complete attack path. Additionally, many false alerts significantly reduce the accuracy of restoring an attack scenario. Against these issues, this paper proposes an approach for attack scenario construction based on a dynamic attack path graph. First, this paper proposes an alert truth rate calculating approach which utilizes mutual information. And the paper constructs the attack path graph by considering multiple dimensions, including calculated alert features and alert truth rate. In addition, an attack chain generation algorithm is proposed to restore the dynamic and complete attack scenario. Secondly, in order to cope with the changing network, the paper introduces a dynamic probabilistic update algorithm that periodically adjusts the attack path as time progresses. Finally, Experimental results show that the proposed approach can recover all attack processes in the dataset, with an algorithmic complexity of O (M × N).

Original languageEnglish
Title of host publication2023 IEEE/CIC International Conference on Communications in China, ICCC 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798350345384
DOIs
StatePublished - 2023
Event2023 IEEE/CIC International Conference on Communications in China, ICCC 2023 - Dalian, China
Duration: 10 Aug 202312 Aug 2023

Publication series

Name2023 IEEE/CIC International Conference on Communications in China, ICCC 2023

Conference

Conference2023 IEEE/CIC International Conference on Communications in China, ICCC 2023
Country/TerritoryChina
CityDalian
Period10/08/2312/08/23

Keywords

  • Attack model
  • Attack path
  • Attack scenario construction
  • Dynamic attack path graph
  • False alert reduction

Fingerprint

Dive into the research topics of 'An Approach for Attack Scenario Construction Based on Dynamic Attack Path Graph'. Together they form a unique fingerprint.

Cite this