【24h】

TRINETR: an intrusion detection alert management systems

机译:TRINETR:入侵检测警报管理系统

获取原文

摘要

In response to the daunting threats of cyber attacks, a promising approach is computer and network forensics. Intrusion detection system is an indispensable part of computer and network forensics. It is deployed to monitor network and host activities including dataflows and information accesses etc. But current intrusion detection products presents many flaws including alert flooding, too many false alerts and isolated alerts etc. We describe an ongoing project to develop an intrusion alert management system $TRINETR. We present a collaborative architecture design for multiple intrusion detection systems to work together to detect real-time network intrusions. The architecture is composed of three parts: alert aggregation, knowledge-based alert evaluation and alert correlation. The architecture is aimed at reducing the alert overload by aggregating alerts from multiple sensors to generate condensed views, reducing false positives by integrating network and host system information into alert evaluation process and correlating events based on logical relations to generate global and synthesized alert report. The first two parts of the architecture have been implemented and the implementation results are presented.
机译:为了响应网络攻击的艰巨威胁,有希望的方法是计算机和网络取证。入侵检测系统是计算机和网络取证的不可或缺的一部分。它部署到监视网络和主机活动,包括数据流和信息访问等,但当前入侵检测产品具有许多缺陷,包括警报洪水,太多错误警报和孤立的警报等。我们描述了开发入侵警报管理系统$的持续项目triinetr。我们提出了一种用于多种入侵检测系统的协作建筑设计,共同努力检测实时网络入侵。该体系结构由三个部分组成:警报聚合,基于知识的警报评估和警报相关性。该体系结构旨在通过从多个传感器聚合警报来减少警报过载,以产生浓缩视图,通过将网络和主机系统信息集成到警报评估过程和基于逻辑关系的关联事件来减少误报,从而生成全局和合成警报报告。已经实现了架构的前两个部分,并提出了实现结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号