首页> 外文会议>Computer Security Applications Conference >Attack Signature Matching and Discovery in Systems Employing Heterogeneous IDS
【24h】

Attack Signature Matching and Discovery in Systems Employing Heterogeneous IDS

机译:在采用异质IDS的系统中攻击签名匹配和发现

获取原文

摘要

Over the past decade, Intrusion Detection Systems (IDS) have improved steadily in the efficiency and effectiveness with which they detect intrusive activity. This is particularly true with signature-based IDS due to progress with intrusion analysis and intrusion signature specification. At the same time system complexity, overall numbers of bugs and security vulnerabilities have been on the increase. This has led to the recognition that in order to operate over the entire attack space, multiple heterogeneous IDS must be used, which need to interoperate with one another, and possibly also with other components of system security. This paper describes our research into developing algorithms for attack signature matching for detecting multi-stage attacks manifested by alerts from heterogeneous IDS. It describes also the testing and preliminary results of that research, and the administrator interface used to analyze the alerts produced by the tests and the results of signature matching.
机译:在过去的十年中,入侵检测系统(IDS)稳定地改善了他们检测到侵入性活动的效率和有效性。由于具有入侵分析和入侵签名规范,因此符合基于签名的ID尤其如此。同时系统复杂性,总数的错误和安全漏洞已经增加。这导致了识别,以便在整个攻击空间上运行,必须使用多个异构ID,这需要彼此互操作,并且也可能与系统安全的其他组件相互互操作。本文介绍了我们对开发攻击符号匹配的开发算法的研究,以检测由异构IDS警报的多级攻击显示的多级攻击。它还描述了该研究的测试和初步结果,以及用于分析测试产生的警报的管理员界面以及签名匹配结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号