Reduce False Alerts, Uncover High-Level Attack Strategies and Predict Attacks in Progress Using Prerequisites of Intrusions
Reduce False Alerts, Uncover High-Level Attack Strategies and Predict Attacks in Progress Using Prerequisites of Intrusions
批准号:
0207297
负责人:
Peng Ning
金额:
$33.0万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2002
资助国家:
美国
项目状态:
已结题
起止时间:
2002-07-01 至 2006-06-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Current intrusion detection systems (IDSs) usually generate many false alerts and often do not detect novel attacks or variations of known attacks. Moreover, most existing IDSs focus on low-level attacks oranomalies; none capture the logical steps or strategies behind these attacks. In situations where there are intensive intrusions, not only will actual alerts be mixed with false alerts, but the number ofalerts will also become unmanageable. As a result, it is difficult for human users or intrusion response systems to understand the nature of the attack and to take appropriate actions.To address these issues, this project will investigate techniques to correlate intrusion alerts on the basis of the prerequisites and consequences of attacks. The research uses a formal and rigorousapproach to study the fundamental issues involved in alert correlation, including representation of prerequisites and consequences of attacks, efficient algorithms to process alerts, expressiveness of the high-level representation mechanisms, effectiveness of the technique in reducing false alerts, impact offalse alerts and undetected attacks on the technique, and methods to predict attacks in progress. Expected impacts of the proposed research include (1) a reduction in the number of false alerts, (2) identification of attackers' high-level strategies, and (3) early configuration of effective defenses against attacks in progress. If successful, the research will lead to better tools for intrusiondetection and thus to improved computer and network security.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
TC: Large: Collaborative Research: Trustworthy Virtual Cloud Computing
-
批准号:0910767
-
项目类别:Standard Grant
-
资助金额:$152.37万
-
财政年份:2009
-
负责人:Peng Ning
-
依托单位:
CT-M: Collaborative Research: A Resilient Real-Time System for a Secure and Reconfigurable Power Grid
-
批准号:0831302
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2008
-
负责人:Peng Ning
-
依托单位:
Collaborative Research: CT-T: A Resilient Real-Time System for a Secure and Reconfigurable Power Grid
-
批准号:0716435
-
项目类别:Standard Grant
-
资助金额:$2.85万
-
财政年份:2007
-
负责人:Peng Ning
-
依托单位:
NeTS-NOSS: Secure, Robust and DoS-Resilient Code Dissemination in Wireless Sensor Networks
-
批准号:0721424
-
项目类别:Standard Grant
-
资助金额:$26.99万
-
财政年份:2007
-
负责人:Peng Ning
-
依托单位:
CAREER: Towards Trustworthy and Resilient Sensor Networks
-
批准号:0447761
-
项目类别:Continuing Grant
-
资助金额:$0.0万
-
财政年份:2005
-
负责人:Peng Ning
-
依托单位:
Collaborative Research: Trustworthy and Resilient Location Discovery in Wireless Sensor Networks
-
批准号:0430223
-
项目类别:Continuing Grant
-
资助金额:$15.0万
-
财政年份:2004
-
负责人:Peng Ning
-
依托单位:
ITR: Integrating Intrusion Detection with Intelligent Visualization and Interaction Strategies
-
批准号:0219315
-
项目类别:Continuing Grant
-
资助金额:$41.51万
-
财政年份:2002
-
负责人:Peng Ning
-
依托单位:
海外基金