首页> 外文会议>International workshop on security >IDS Alert Priority Determination Based on Traffic Behavior
【24h】

IDS Alert Priority Determination Based on Traffic Behavior

机译:IDS根据流量行为提醒优先级确定

获取原文

摘要

With the increase in the variety of devices connected to the Internet, each with their own vulnerabilities, we are currently observing an explosion of cyber attacks patterns. Furthermore, the overwhelming number of alerts from security sensors, such as intrusion detection systems (IDSs), makes it impossible to take appropriate countermeasures against attacks. A method to prioritize IDS alerts is therefore required for the next generation of security operation centers (SOCs). To this end, we have developed an IDS alert priority determination method that combines IDS alert information with traffic behavior and uses the difference in the distribution of traffic behavior to determine the priority of the alerts. We performed experiments with 2 million IDS alerts and 20 billion traffic flows in a real large-scale environment over two months and found that our method could identify 553 IDS alerts out of 2 million as high priority, which is a small enough number for SOC analysts to investigate them in detail.
机译:随着多种设备的增加,各种设备,每个设备都有自己的漏洞,我们目前正在观察网络攻击模式的爆炸。此外,从安全传感器(例如入侵检测系统(IDS))的压倒性警报数量使得无法对攻击采取适当的对策。因此,下一代安全操作中心(SOC)需要优先考虑IDS警报的方法。为此,我们开发了一个IDS警报优先级确定方法,该确定方法将IDS警报信息与流量行为组合,并使用流行行为分布的差异来确定警报的优先级。我们在两个月内进行了200万IDS警报和200亿个交通流量的实验,超过两个月的实际情况,发现我们的方法可以识别553个IDS警报,其中200万件为高优先级,这是SoC分析师的一小部分详细研究它们。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号