首页> 外文会议> >The Honeynet Quarantine: Reducing Collateral Damage Caused by Early Intrusion Response
【24h】

The Honeynet Quarantine: Reducing Collateral Damage Caused by Early Intrusion Response

机译:Honeynet隔离区:减少早期入侵响应引起的附带损害

获取原文

摘要

Anomaly based intrusion detection is inherently subject to false alarms. Fast and automated intrusion response based on this type of intrusion detection will cause significant usage restrictions for falsely suspected systems. To avoid these negative effects without sacrificing detection sensitivity or increasing the risk for the production network inadequately, we propose a scheme combining anomaly-based IDS with Honeynet concepts and link layer based VLANs. In addition to introducing the concept, we will describe a proof-of-concept implementation and report results from some lab tests confirming the benefits of this approach.
机译:基于异常的入侵检测固有地会遭受错误警报。基于这种类型的入侵检测的快速,自动的入侵响应将导致对可疑系统的重大使用限制。为了避免这些负面影响而不牺牲检测灵敏度或不充分增加生产网络的风险,我们提出了一种将基于异常的IDS与Honeynet概念以及基于链路层的VLAN相结合的方案。除了介绍该概念之外,我们还将描述概念验证的实现,并报告一些实验室测试的结果,这些结果证实了这种方法的好处。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号