Performance of Snort on DARPA Dataset and different False Alert Reduction techniques
Performance of Snort on DARPA Dataset and different False Alert Reduction techniques
复制标题
Snort 在 DARPA 数据集上的性能和不同的误报减少技术
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Ritu Nagpal
中科院分区:
文献类型:
--
作者:
Ayushi Chahal;Ritu Nagpal
Security is main goal of Internet community these days and endless techniques and tools have arrived to tackle with the security threats over the network. Snort is one of these techniques, which is a kind of Network Intrusion Detection System. Snort is a programming tool that allows user to write their own detection rules for any kind of attack. DARPA dataset is the one dataset used by the IDS researchers. In this paper, we study Snort, different attacks in DARPA dataset, analyze the DARPA 2000 dataset for its various phases with snort and the efficiency with which snort manages these attacks. The paper focuses on one of the main flaw of Snort i.e. huge number of false positives and different types of methods that have been proposed by the researchers to reduce these false alerts generated by Snort.