Research of snort rule extension and APT detection based on APT network behavior analysis

Yan Cui*, Jingfeng Xue, Yong Wang, Zhenyan Liu, Ji Zhang

*此作品的通讯作者

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

At present, APT attack detection has become the focus of the network security protection field. APT attacks are one of the most difficult attacks in cyber attacks. The complexity and variability of APT attack behavior greatly increases the difficulty of attack detection. In order to cope with APT attack, some well-known network security companies at home and abroad have developed a commercial APT intrusion detection system. This highly targeted attack can not be identified by the traditional intrusion detection system. Therefore, in order to deal with this new type of cyber attack. The paper proposes a new method to detect APT attack from different organizations. Data mining algorithm is used to analyze every organization’s APT network attack behavior and obtain association rules, so as to customize the design of the Snort rules and apply them to intrusion detection system. Experiments have shown that the evaluation index of the intrusion detection system using the extended Snort rule is significantly better than the traditional Snort intrusion detection system when detecting the same test data. The precision of the extended Snort intrusion detection system is as high as 98.3%, and the false alarm rate is almost 0, which ultimately achieves the purpose of APT detection.

源语言英语
主期刊名Trusted Computing and Information Security - 12th Chinese Conference, CTCIS 2018, Revised Selected Papers
编辑Huanguo Zhang, Bo Zhao, Fei Yan
出版商Springer Verlag
51-64
页数14
ISBN(印刷版)9789811359125
DOI
出版状态已出版 - 2019
活动12th Chinese Conference on Trusted Computing and Information Security, CTCIS 2018 - Wuhan, 中国
期限: 18 10月 201818 10月 2018

出版系列

姓名Communications in Computer and Information Science
960
ISSN(印刷版)1865-0929

会议

会议12th Chinese Conference on Trusted Computing and Information Security, CTCIS 2018
国家/地区中国
Wuhan
时期18/10/1818/10/18

指纹

探究 'Research of snort rule extension and APT detection based on APT network behavior analysis' 的科研主题。它们共同构成独一无二的指纹。

引用此