首页> 外文会议>WSEAS International Conferences >Strategic Alert Throttling for Intrusion Detection Systems
【24h】

Strategic Alert Throttling for Intrusion Detection Systems

机译:用于入侵检测系统的战略警报限制

获取原文

摘要

Network intrusion detection systems are themselves becoming targets of attackers. Alert flood attacks may be used to conceal malicious activity by hiding it among a deluge of false alerts sent by the attacker. Although these types of attacks are very hard to stop completely, our aim is to present techniques that improve alert throughput and capacity to such an extent that the resources required to successfully mount the attack become prohibitive. The key idea presented is to combine a token bucket filter with a real time correlation algorithm. The proposed algorithm throttles alert output from the IDS when an attack is detected. The attack graph used in the correlation algorithm is used to make sure that alerts crucial to forming strategies are not discarded by throttling.
机译:网络入侵检测系统本身就成为攻击者的目标。警报洪水攻击可用于隐藏恶意活动,通过隐藏攻击者发送的策略警报中。虽然这些类型的攻击非常难以完全停止,但我们的目标是提高提高警报吞吐量和能力的技术,以便成功安装攻击所需的资源变得令人望而却步。所提出的关键的想法是将令牌桶滤波器与实时相关算法组合。当检测到攻击时,所提出的算法会限制来自ID的警报输出。相关算法中使用的攻击图用于确保通过节流不会丢弃对形成策略至关重要的警报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号