Attack scenario reconstruction is a crucial subtask of network security situation awareness. To obtain comprehensive attack scenarios, reconstruction methods need to analyze traffic, alerts, and logs from the monitored network. However, such security data typically features high volume and redundancy, making it difficult to identify relevant attack scenarios in complex network environments. To address this challenge, this paper proposes a semantic-enhanced attack scenario reconstruction method. The method constructs a property graph containing aggregated alerts and network events based on modular ontologies, and employs a projection graph construction approach that incorporates alert contexts. We utilize ontology to analyze relationships between aggregated alerts and attacks, and extract potential attack behavior chains combined with temporal information. Experiments demonstrate that our approach achieves superior completeness and soundness compared to existing methods, while maintaining computational efficiency in processing large-scale security data.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Semantic-Enhanced Attack Scenario Reconstruction Using Property Graph and Modular Ontologies

  • Yixuan Wang,
  • Bo Zhao,
  • Xiaofu Song,
  • Junru Peng

摘要

Attack scenario reconstruction is a crucial subtask of network security situation awareness. To obtain comprehensive attack scenarios, reconstruction methods need to analyze traffic, alerts, and logs from the monitored network. However, such security data typically features high volume and redundancy, making it difficult to identify relevant attack scenarios in complex network environments. To address this challenge, this paper proposes a semantic-enhanced attack scenario reconstruction method. The method constructs a property graph containing aggregated alerts and network events based on modular ontologies, and employs a projection graph construction approach that incorporates alert contexts. We utilize ontology to analyze relationships between aggregated alerts and attacks, and extract potential attack behavior chains combined with temporal information. Experiments demonstrate that our approach achieves superior completeness and soundness compared to existing methods, while maintaining computational efficiency in processing large-scale security data.