20.06.2015 Views

ossim - AlienVault

ossim - AlienVault

ossim - AlienVault

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3.6.2.2 Method 2: Correlation Using Sequences of Events<br />

The Sequences Panel<br />

The basic idea for detecting a sequence of patterns is simple: just create a list of rules like “if<br />

you receive event A and then B and then C, perform action D.”<br />

To that end we use the sequences panel, where we define lists of rules for each sequence of<br />

events that we want to define.<br />

The complexity of the panel depends on the capacity of those rules for abstraction and OSSIM’s<br />

ability to analyze a variety of input.<br />

Our panel can execute sequences with the following characteristics:<br />

• Ability to define variable origins and destinations<br />

• Accept both pattern input from detectors and indicator input from monitors<br />

• Define the priority and reliability of new alerts<br />

• Use “elastic” variables, or variables that can measure an event to define priority or<br />

reliability (e.g. total denial of service -> high priority, 50% denial -> medium priority, 15%<br />

denial -> low priority)<br />

• Recursive architecture—we can create objects by correlating rules that function as<br />

detectors or monitors in new rules<br />

19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!