A Language Driven Intrusion Detection System for Event and Alert Correlation
نویسندگان
چکیده
It is well known that security prevention mechanisms are not sufficient to protect efficiently an information system. Intrusion detection systems are required. But these systems present many imperfections. In particular, they can either generate false positives (i.e., alarms that should not be produced) or miss attacks (false negatives). However, the main problem is the generation of false positives that can overwhelm the information system administrator. In this paper, we follow the notion of correlation proposed by others. The objective is to aim at correlating either events in the analyser or alerts in the manager. We first present the ADeLe language, which provides a way to define the correlation properties. Then we present which algorithms have been carried out in our IDS to handle ADeLe signatures. Finally, we show the stress tests that have been applied to the probe algorithms that we have implemented.
منابع مشابه
Real-Time intrusion detection alert correlation and attack scenario extraction based on the prerequisite consequence approach
Alert correlation systems attempt to discover the relations among alerts produced by one or more intrusion detection systems to determine the attack scenarios and their main motivations. In this paper a new IDS alert correlation method is proposed that can be used to detect attack scenarios in real-time. The proposed method is based on a causal approach due to the strength of causal methods in ...
متن کاملAlert correlation and prediction using data mining and HMM
Intrusion Detection Systems (IDSs) are security tools widely used in computer networks. While they seem to be promising technologies, they pose some serious drawbacks: When utilized in large and high traffic networks, IDSs generate high volumes of low-level alerts which are hardly manageable. Accordingly, there emerged a recent track of security research, focused on alert correlation, which ext...
متن کاملOntology-Based Inter-Domain Event Correlation
The notion of event correlation has been around for some time. Most recently, event correlation has gotten a significant amount of attention in the intrusion detection community under the topic of alert correlation. The principles behind event correlation, however, can also be used to relate events in seemingly heterogeneous domains such as access control and intrusion detection. To address the...
متن کاملAn Approach to Sensor Correlation
We present an approach to intrusion detection (ID) sensor correlation that considers the problem in three phases: event aggregation, sensor coupling, and meta alert fusion. The approach is well suited to probabilistically based sensors such as EMERALD eBayes. We demonstrate the efficacy of the EMERALD alert thread mechanism, the sensor coupling in eBayes, and a prototype alert fusion capability...
متن کاملA Review of Intrusion Alerts Correlation Frameworks
The advancement of modern computers, networks and internet has led to the widespread adoption and application of Information Communication Technology in modern organizations. As a result, large amount of information is generated, processed and distributed through digital devices. On the other side, digital crimes have increased in number and sophistication and they compromise the organization’s...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2004