ossim - AlienVault
ossim - AlienVault
ossim - AlienVault
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
3.6.2.2 Method 2: Correlation Using Sequences of Events<br />
The Sequences Panel<br />
The basic idea for detecting a sequence of patterns is simple: just create a list of rules like “if<br />
you receive event A and then B and then C, perform action D.”<br />
To that end we use the sequences panel, where we define lists of rules for each sequence of<br />
events that we want to define.<br />
The complexity of the panel depends on the capacity of those rules for abstraction and OSSIM’s<br />
ability to analyze a variety of input.<br />
Our panel can execute sequences with the following characteristics:<br />
• Ability to define variable origins and destinations<br />
• Accept both pattern input from detectors and indicator input from monitors<br />
• Define the priority and reliability of new alerts<br />
• Use “elastic” variables, or variables that can measure an event to define priority or<br />
reliability (e.g. total denial of service -> high priority, 50% denial -> medium priority, 15%<br />
denial -> low priority)<br />
• Recursive architecture—we can create objects by correlating rules that function as<br />
detectors or monitors in new rules<br />
19