Investigating the problem of IDS false alarms: An experimental study using Snort

Investigating the problem of IDS false alarms: An experimental study using Snort
复制标题

调查 IDS 误报问题:使用 Snort 的实验研究

DOI:
--
复制
发表时间:
2008
期刊:
IFIP International Information Security Conference
影响因子:
--
通讯作者:
N. Clarke
N. Clarke
中科院分区:
--
文献类型:
--
作者:
Gina C. Tjhai;M. Papadaki;S. Furnell;N. Clarke

文献摘要

被引文献

相似文献

IDS可以在整体安全基础架构中发挥至关重要的作用,这是在安全网络架构设计,安全程序设计和防火墙之后对攻击的最后防御[1]。尽管IDS技术已成为公司网络体系结构的重要组成部分,但检测入侵的艺术仍然远非完美。一个重要的问题是错误的警报,这与ID被错误地归类为恶意的合法活动相对应。从大量警报中识别出真正的警报是一项复杂且耗时的任务。因此,减少错误警报是确保ID效率和可用性的严重问题[2]。降低错误警报率的常见技术是执行调整程序。这可以通过将签名集适应特定环境并禁用与之相关的签名[8]来完成,因为仅在特定的OS平台中存在某些漏洞。但是,尽管这可以提供减少错误警报数量的手段,但该程序也可以增加丢失值得注意的事件的风险。因此,调整过程实际上是减少错误警报和维护安全级别之间的权衡。这通常会使管理员难以确定理想检测率和有错误警报的可能性之间的适当平衡。此外,调整需要通过合格的IT人员对环境进行彻底检查,并且需要经常更新以跟上发现的新漏洞或威胁的流动[26]。
IDS can play a vital role in the overall security infrastructure, as one last defence against attacks after secure network architecture design, secure program design and firewalls [1]. Although IDS technology has become an essential part of corporate network architecture, the art of detecting intrusions is still far from perfect. A significant problem is that of false alarms, which correspond to legitimate activity that has been mistakenly classed as malicious by the IDS. Recognising the real alarms from the huge volume of alarms is a complicated and time-consuming task. Therefore, reducing false alarms is a serious problem in ensuring IDS efficiency and usability [2]. A common technique for reducing the false alarm rate is by performing a tuning procedure. This can be done by adapting the set of signatures to the specific environment and disabling the signatures that are not related to it [8], based on the fact that some vulnerabilities exist in a particular OS platform only. However, although this can offer a means of reducing the number of false alarms, the procedure can also increase the risk of missing noteworthy incidents. Therefore, the tuning process is actually a trade-off between reducing false alarms and maintaining the security level. This often leaves administrators with the difficulty of determining a proper balance between an ideal detection rate and the possibility of having false alarms. Furthermore, tuning requires a thorough examination of the environment by qualified IT personnel, and requires frequently updating to keep up with the flow of new vulnerabilities or threats discovered [26].