首页> 外文会议>Computer Security Applications Conference >Log Correlation for Intrusion Detection: A Proof of Concept
【24h】

Log Correlation for Intrusion Detection: A Proof of Concept

机译:入侵检测的对数相关性:概念证明

获取原文

摘要

Intrusion detection is an important part of networked systems security protection. Although commercial products exist, finding intrusions has proven to be a difficult task with limitations under current techniques. Therefore, improved techniques are needed. We argue the need for correlating data among different logs to improve intrusion detection systems accuracy. We show how different attacks are reflected in different logs and argue that some attacks are not evident when a single log is analyzed. We present experimental results using anomaly detection for the virus Yaha. Through the use of data mining tools (RIPPER) and correlation among logs we improve the effectiveness of an intrusion detection system while reducing false positives.
机译:入侵检测是网络系统安全保护的重要组成部分。虽然存在商业产品,但发现入侵已被证明是当前技术下有局限性的艰巨任务。因此,需要改进的技术。我们认为需要将数据与不同日志之间的数据相关,以提高入侵检测系统精度。我们展示了不同日志中的不同攻击如何反映,并且在分析单个日志时,某些攻击不明显。我们使用对病毒雅加的异常检测来提出实验结果。通过使用数据挖掘工具(RIPPER)和日志之间的相关性,我们提高入侵检测系统的有效性,同时减少了误报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号