首页> 外文会议> >An Intelligent Detection and Response Strategy to False Positives and Network Attacks: Operation of Network Quarantine Channels and Feedback Methods to IDS
【24h】

An Intelligent Detection and Response Strategy to False Positives and Network Attacks: Operation of Network Quarantine Channels and Feedback Methods to IDS

机译:误报和网络攻击的智能检测和响应策略:网络隔离通道的操作和对IDS的反馈方法

获取原文

摘要

Network-based Intrusion Detection Systems (IDSs) are designed to monitor potential attacks in network infrastructures. IDSs trigger alerts of potential attacks in network security. These alerts are examined by security analysts to see if they are benign or attacks. However these alerts consist of high volumes of false positives, which are triggered by suspicious but normal, benign connections. These high volumes of false positives makes manual analysis of the alerts difficult and inefficient in real-time detection and response. In this paper we discuss briefly the significance of false positives and their impact on intrusion detection and response. Then we propose a novel approach for an efficient intelligent detection and response through the reduction of false positives. The intelligent strategy consists of technique with multiple zones for isolation and interaction with the hosts from which the packets were sent in real-time. We propose multiple feedback methods to the IDS monitor and database to indicate the status of the alerts. These innovative approaches, using NQC and feedback mechanisms enhance the capability of the IDS to detect threats and benign attacks. This is accomplished by applying adaptive rules to the alert filters and policies of the IDS network sensors.
机译:基于网络的入侵检测系统(IDS)旨在监视网络基础结构中的潜在攻击。 IDS会触发有关网络安全潜在攻击的警报。这些警报由安全分析人员检查,以查看它们是否是良性或攻击性的。但是,这些警报由大量误报组成,这些误报是由可疑但正常的良性连接触发的。这些大量的误报使手动分析警报变得困难且效率低下,无法实时检测和响应。在本文中,我们简要讨论了误报的重要性及其对入侵检测和响应的影响。然后,我们提出了一种新颖的方法,可以通过减少误报来进行有效的智能检测和响应。智能策略由具有多个区域的技术组成,这些区域用于隔离并与实时发送数据包的主机进行交互。我们向IDS监视器和数据库提出了多种反馈方法,以指示警报的状态。这些使用NQC和反馈机制的创新方法增强了IDS检测威胁和良性攻击的能力。这是通过将自适应规则应用于IDS网络传感器的警报筛选器和策略来完成的。

著录项

  • 来源
    《》|2006年|P.16-21|共6页
  • 会议地点
  • 作者

    Hooper; E.;

  • 作者单位
  • 会议组织
  • 原文格式 PDF
  • 正文语种
  • 中图分类 工业技术;
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号