期刊文献+

基于环境信息改进入侵警报正确率 被引量:2

Improving the Efficiency of Intrusion Alarm Based on Environment Information
下载PDF
导出
摘要 通常误用检测所定义之攻击特征仅限于单一信息,而经由单一信息所产生的警报,由于针对某些攻击无法精确做出判断,所以误报比例相对较高。在文中,针对误用网络型入侵检测系统建立一个警报过滤机制,该机制找出攻击成功时所需具备的环境条件。当入侵检测系统发现可疑入侵时,依据环境条件加以实时确认查核。根据这些环境异质信息,可明显减少误报的发生,并且不至于将重要的警报给删除。实验结果证明,所提出之过滤机制可以有效地减少误报,同时不影响检测率。 In intrusion detection systems adopting misuse detection methods,the attack signatures are mostly characterized with information from single data source.Without utilizing other available information,the accuracy of judgment made in generating alarm may not be satisfactory.This paper proposes an alarm filtering scheme to improve the efficiency of misuse-type network intrusion detection system.Through careful analysis,a preliminarily recognized attack threat can be verified against envrionment information in determining if an attack may really succeed before it is reported.The proposed scheme has been implemented.Experiment result shows,with the environment information,the occurrences of false alarm are obviously reduced and none of the real alarms are among those non-reported ones.
出处 《计算机工程与应用》 CSCD 北大核心 2005年第17期143-146,155,共5页 Computer Engineering and Applications
基金 国家网络与信息安全保障持续发展计划(编号:2004-研1-917-C-017)
关键词 入侵检测 误用检测 减少误报 报警过滤 环境信息 intrusion detection,misuse detection,false alarm reduction,alarm filtering,environment information
  • 相关文献

参考文献7

  • 1Steven R,Snapp.DIDS(Distributed Intrusion Detection System)-Motivation,Architecture,and An Early Prototype[C].In:Proc 14th National Computer Security Conference,Washington DC,USA,1991:167-176.
  • 2Sang Jun Han,Sung Bae Cho.Rule-based integration of multiple measure models for effective intrusion detection[C].In:IEEE International Conference on Systems,Man and Cybernetics,2003;1:120-125.
  • 3Magnus Ahngren,Ulf Lindqvist.Application-Integrated Data Collection for Security Monitoring[C].In:Recent Advances in Intrusion Detection(BALD 2001) ,Davis,California,2001:22-36.
  • 4Sandeep Kumar.CLASSIFICATION AND DETECTION OF COMPUTER INTRUSIONS[D].Purdue University, 1995.
  • 5Michael Howard,Jon Pincus,Jeannette Wing.Measuring Relative Attack Surfaces[C].In:Proceedings of Workshop on Advanced Developments in Software and Systems Security,2003:178-189.
  • 6Klaus Julisch.Dealing with False Positives in Intrusion Detection[C].In:Recent Advances in Intrusion Detection(RAID 2000),Toulouse,2000:113-119.
  • 7.[EB/OL].hap,//www.sourceftre.com/services/snort_ndes.html.,.

同被引文献47

  • 1马传香,李庆华,王卉.入侵检测研究综述[J].计算机工程,2005,31(3):4-6. 被引量:26
  • 2[13]J Wang,I Lee.Measuring false-positive by automated real-time correlated hacking behavior analysis.ISC 2001,Malaga,Spain,2001
  • 3[14]Kwok Ho Law,Lam For Kwok.IDS false alarm filtering using KNN classifier.WISA 2004,Jeju Island,Korea,2004
  • 4[15]Tadeusz Pietraszek.Using adaptive alert classification to reduce false positives in intrusion detection.RAID 2004,Sophia Antipolis,France,2004
  • 5[16]Moon Sun Shin,Eun Hee Kim,Keun Ho Ryu.False alarm classification model for network-based intrusion detection system.IDEAL 2004,Exeter,UK,2004
  • 6[17]Yan Zhai,Peng Ning,Purash Iyer.Reasoning about complementary intrusion evidence.The 20th Annual Computer Security Applications Conference,Tucson,USA,2004
  • 7[18]P Ning,D Xu.Hypothesizing and reasoning about attacks missed by intrusion detection systems.ACM Trans on Information and System Security,2004,7(4):1-37
  • 8[19]Xinzhou Qin,Wenke Lee.Statistical causality analysis of INFOSEC alert data.The 6th Int'l Symp on Recent Advances in Intrusion Detection (RAID 2003),Pittsburgh,PA,USA,2003
  • 9[20]Xinzhou Qin,Wenke Lee.Discovering novel attack strategies from INFOSEC alerts.ESORICS 2004,Sophia Antipolis,2004
  • 10[21]William Yurcik.Controlling intrusion detection systems by generating false positives:Squealing proof-of-concept.The 27th Annual IEEE Conf on Local Computer Networks (LCN),Tampa,FL,USA,2002

引证文献2

二级引证文献2

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部