首页> 外文会议>IFIP/IEEE Symposium on Integrated Network and Service Management >Exchanging Security Events: Which And How Many Alerts Can We Aggregate?
【24h】

Exchanging Security Events: Which And How Many Alerts Can We Aggregate?

机译:交换安全事件:我们可以汇总哪些警报?

获取原文

摘要

The exchange of security alerts is a current trend in network security and incident response. Alerts from network intrusion detection systems are shared among organizations so that it is possible to see the "big picture" of current security situation. However, the quality and redundancy of the input data seem to be underrated. We present four use cases of aggregation of the alerts from network intrusion detection systems. Alerts from a sharing platform deployed in the Czech national research and education network were examined in a case study. Volumes of raw and aggregated data are presented and a rule of thumb is proposed: up to 85 % of alerts can be aggregated. Finally, we discuss the practical implications of alert aggregation for the network intrusion detection system, such as (in)completeness of the alerts and optimal time windows for aggregation.
机译:安全警报的交换是网络安全和事件响应的当前趋势。来自网络入侵检测系统的警报在组织之间共享,以便可以看到当前安全情况的“大图”。但是,输入数据的质量和冗余似乎被低估了。我们在网络入侵检测系统中展示了警报的聚合汇总。在捷克国家研究和教育网络中部署的共享平台的警报在案例研究中进行了审查。提出了原始和汇总数据的卷,提出了规则:高达85%的警报可以汇总。最后,我们讨论了网络入侵检测系统的警报聚合的实际影响,例如(in)警报的完整性和聚合的最佳时间窗口。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号