Intrusion Alert Correlation Technique Analysis for Heterogeneous Log

Intrusion Alert Correlation Technique Analysis for Heterogeneous Log
复制标题

DOI:
--
复制
发表时间:
2008-09
期刊:
--
影响因子:
--
通讯作者:
R. Yusof;S. R. Selamat;S. Sahib
R. Yusof;S. R. Selamat;S. Sahib
中科院分区:
其他
文献类型:
--
作者:
R. Yusof;S. R. Selamat;S. Sahib

文献摘要

被引文献

相似文献

入侵警报关联是一个多步骤的过程,它接收来自异构日志资源的警报作为输入,并生成对网络上恶意活动的高级描述。本研究的目的是分析当前的警报相关技术,并确定每种技术中可以改善入侵检测系统(IDS)问题的重要标准,例如容易发生警报泛滥,上下文问题,假警报和可扩展性问题。对现有的预警相关技术进行了综述和分析。在此基础上,提出了改进现有预警相关技术的六个能力准则。它们是警报缩减、警报聚类、识别多步攻击、减少假警报、检测已知攻击和检测未知攻击的能力。
Summary Intrusion alert correlation is multi-step processes that receives alerts from heterogeneous log resources as input and produce a high-level description of the malicious activity on the network. The objective of this study is to analyse the current alert correlation technique and identify the significant criteria in each technique that can improve the Intrusion Detection System (IDS) problem such as prone to alert flooding, contextual problem, false alert and scalability. The existing alert correlation techniques had been reviewed and analysed. From the analysis, six capability criteria have been identified to improve the current alert correlation technique. They are capability to do alert reduction, alert clustering, identify multistep attack, reduce false alert, detect known attack and detect unknown attack.