首页> 外文会议>International Conference on Information Assurance and Security >Context-aware intrusion alerts verification approach
【24h】

Context-aware intrusion alerts verification approach

机译:上下文感知入侵警报验证方法

获取原文

摘要

Intrusion detection systems (IDSs) produce a massive number of intrusion alerts. A huge number of these alerts are false positives. Investigating false positive alerts is an expensive and time consuming process, and as such represents a significant problem for intrusion analysts. This shows the needs for automated approaches to eliminate false positive alerts. In this paper, we propose a novel alert verification and false positives reduction approach. The proposed approach uses context-aware and semantic similarity to filter IDS alerts and eliminate false positives. Evaluation of the approach with an IDS dataset that contains massive number of IDS alerts yields strong performance in detecting false positive alerts.
机译:入侵检测系统(IDS)会产生大量的入侵警报。这些警报中有大量是误报。调查假阳性警报是一个昂贵且耗时的过程,因此对于入侵分析人员而言是一个重大问题。这表明需要采用自动化方法来消除误报。在本文中,我们提出了一种新颖的警报验证和误报减少方法。所提出的方法使用上下文感知和语义相似性来过滤IDS警报并消除误报。使用包含大量IDS警报的IDS数据集对该方法进行评估,可以在检测假阳性警报方面表现出出色的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号