Performance of Snort on DARPA Dataset and different False Alert Reduction techniques

Performance of Snort on DARPA Dataset and different False Alert Reduction techniques
复制标题

Snort 在 DARPA 数据集上的性能和不同的误报减少技术

DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Ritu Nagpal
Ritu Nagpal
中科院分区:
--
文献类型:
--
作者:
Ayushi Chahal;Ritu Nagpal

文献摘要

被引文献

相似文献

安全是当今互联网社区的主要目标,并且已经有无数的技术和工具来应对网络上的安全威胁。 Snort就是其中一种技术,它是一种网络入侵检测系统。 Snort 是一种编程工具,允许用户为任何类型的攻击编写自己的检测规则。 DARPA 数据集是 IDS 研究人员使用的数据集。在本文中,我们研究了 Snort、DARPA 数据集中的不同攻击,分析了 DARPA 2000 数据集的 Snort 各个阶段以及 Snort 管理这些攻击的效率。本文重点讨论了 Snort 的主要缺陷之一,即大量误报,以及研究人员提出的不同类型的方法来减少 Snort 产生的这些误报。
Security is main goal of Internet community these days and endless techniques and tools have arrived to tackle with the security threats over the network. Snort is one of these techniques, which is a kind of Network Intrusion Detection System. Snort is a programming tool that allows user to write their own detection rules for any kind of attack. DARPA dataset is the one dataset used by the IDS researchers. In this paper, we study Snort, different attacks in DARPA dataset, analyze the DARPA 2000 dataset for its various phases with snort and the efficiency with which snort manages these attacks. The paper focuses on one of the main flaw of Snort i.e. huge number of false positives and different types of methods that have been proposed by the researchers to reduce these false alerts generated by Snort.