This paper presents a factor graph based framework (named AttackTagger) for highaccuracy and preemptive detection of attacks. We use security logs ofreal-incidents that occurred over a six-year period at the National Center forSupercomputing Applications (NCSA) at the University of Illinois to evaluateAttackTagger. Our data consist of attacks that led directly to the target systembeing compromised, i.e., not detected in advance, either by the securityanalysts or by intrusion detection systems. AttackTagger can detect 74 percentof attacks before the system misuse. AttackTagger uncovered six hidden attacksthat were not detected by security analysts.
【 预 览 】
附件列表
Files
Size
Format
View
An experiment using factor graph for early attack detection