Research Article

Constructing APT Attack Scenarios Based on Intrusion Kill Chain and Fuzzy Clustering

Table 1

The meaning of each attribute.

The attribute of an alarmMeaning

timestampThe time when the attack occurred
sIPThe source IP address
dIPThe destination IP address
sPortThe source port
dPortThe destination port
alarm_eventThe IDS alarm event