False Positive Decrement for Snort Intrusion Detection

False Positive Decrement for Snort Intrusion Detection
复制标题

Snort 入侵检测的误报减少

DOI:
--
复制
发表时间:
2012
期刊:
影响因子:
--
通讯作者:
M. Lertwatechakul
M. Lertwatechakul
中科院分区:
--
文献类型:
--
作者:
Siwnart Thian;M. Lertwatechakul

文献摘要

被引文献

相似文献

Snort是一个免费的软件入侵检测系统(IDS)。 Snort使用基于规则的方法来检测入侵,以便基于其主动规则集的性能和capab1hty。当网络受到攻击时。 Snort将向管理员生成警报。到目前为止,如果规则集不涵盖恶意活动和攻击行为,则可能发生虚假负面。如果规则集不适用于计算机和网络,则可能发生误报,因为太多的误报事件可能会超载snort,并且可能是失败入侵检测的导入因素。由于上述问题,这项工作的主要目的是开发系统以减少对Snort的假阳性。该系统应用神经网络。神经网络由良好的数据集培训。输入数据是环境中的参数,因为发出警报和来自Internet的参考数据,神经网络会为攻击的分数产生可能为0-100的攻击分数。如果质量低0-50,则导致低质量的特定规则警报是由管理员禁用的。最后,获得的结果表明,鼻涕的性能提高了W1th。他的假阳性约为72.78%。
Snort is a freeware Intrusion Detection System (IDS). Snort uses rule-based approach to detect intrusions so that its performance and capab1hty based on its active rule set. When a network is attacked. Snort will generate alerts to the administrator. So far false negative could be occurred in case the rule set do not cover malicious activities and attack behaviors. While false positive could be occurred in case the rule set is not appropriate for the computer and network Since too many false positive event could overload Snort and may be an import factor to fail intrusions detection. Because of the mentioned problem, !he main objective of this work is to develop the system as to reduce false positive of Snort. The system applies the neural network. The neural network was trained by well-form dataset. Input data were parameters in the environment as alert occurring and reference data from the Internet The neural network generates a score for an attack that could be rang 0 - 100. In case of low quality alert 0 - 50, the specific rules which caused low quality alert were disabling by administrator. Finally the obtained results show that the performance of Snort increased w1th .he false positives about 72.78%.