作者: Changwei Liu , Anoop Singhal , Duminda Wijesekera
DOI: 10.1007/978-3-642-41148-9_16
关键词:
摘要: Probabilistic evidence graphs can be used to model network intrusion and the underlying dependencies support forensic analysis. The provide a means for linking probabilities associated with different attack paths available evidence. However, current work focused on assumes that all expressed using single, small graph. This paper presents an algorithm merging or without corresponding application of file server database scenario yields integrated graph shows global scope attack. provides broader context better understandability than multiple local graphs.