Rule generalisation in intrusion detection systems using SNORT

Rule generalisation in intrusion detection systems using SNORT
复制标题

DOI:
10.1504/ijesdf.2007.013596
复制
发表时间:
2007-01-01
影响因子:
0.8
通讯作者:
Hesketh-Roberts, Thomas
Hesketh-Roberts, Thomas
中科院分区:
其他
文献类型:
--
作者:
Aickelin, Uwe;Twycross, Jamie;Hesketh-Roberts, Thomas

文献摘要

被引文献

相似文献

入侵检测系统(ids)为计算机系统和网络提供了重要的安全保障。IDS的职责是检测可疑或不可接受的系统和网络活动,并提醒系统管理员注意此活动。大多数IDS使用一组签名来定义什么是可疑流量,SNORT是一种流行的、正在积极开发的开源IDS,它使用这样一组被称为SNORT规则的签名。我们的目标是确定一种方法,通过一般化规则来识别新的攻击,从而进一步开发SNORT。特别是,我们尝试放松和改变当前SNORT规则的条件和参数,使用与经典规则学习操作符(如泛化和专门化)类似的方法。我们通过标准数据集的实验证明了我们方法的有效性,并表明我们能够检测到以前未检测到的各种攻击变体。
Intrusion Detection Systems (IDSs) provide an important layer of security for computer systems and networks. An IDS's responsibility is to detect suspicious or unacceptable system and network activity and to alert a systems administrator to this activity. The majority of IDSs use a set of signatures that define what suspicious traffic is, and SNORT is one popular and actively developing open-source IDS that uses such a set of signatures known as SNORT rules. Our aim is to identify a way in which SNORT could be developed further by generalising rules to identify novel attacks. In particular, we attempted to relax and vary the conditions and parameters of current SNORT rules, using a similar approach to classic rule learning operators such as generalisation and specialisation. We demonstrate the effectiveness of our approach through experiments with standard data sets and show that we are able to detect previously undetected variants of various attacks.