首页> 外文会议>2011 CSI International Symposium on Computer Science and Software Engineering >A new framework for online rule threshold adjustment in intrusion detection
【24h】

A new framework for online rule threshold adjustment in intrusion detection

机译:入侵检测在线规则阈值调整的新框架

获取原文

摘要

Generally, rule-based systems work to make sense of a large volume of alerts generated by the intrusion detection systems (IDSs) every minute. Hence, it is very significant to verify that these systems are error-free and that the rules are suitable for the current network. This topic is addressed by Rule Adjustment, which automatically adjusts the rules based on the current network environment. The problem with the rule adjustment is to adjust the internal thresholds and to keep the structure unchanged. In this paper, we propose a method for adjusting the rules, online. This method does the threshold adjustment without changing the structure of the rules. Here, our approach for online threshold adjustment is to monitor the alerts and detect constant changes in them. And then, we adjust the appropriate thresholds. We have implemented this method and evaluated it using real-world datasets. Our approach was successfully able to adjust the rules in all the cases with marginal error.
机译:通常,基于规则的系统可以使入侵检测系统(IDS)每分钟生成大量警报。因此,验证这些系统没有错误并且规则适用于当前网络非常重要。规则调整解决了该主题,规则调整根据当前的网络环境自动调整规则。规则调整的问题是调整内部阈值并保持结构不变。在本文中,我们提出了一种在线调整规则的方法。此方法在不更改规则结构的情况下进行阈值调整。在这里,我们用于在线阈值调整的方法是监视警报并检测警报中的不断变化。然后,我们调整适当的阈值。我们已经实现了这种方法,并使用了真实的数据集对其进行了评估。我们的方法能够成功地在所有带有边际误差的情况下调整规则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号