首页> 外文会议>International Workshop on Security, Privacy and Trust in Pervasive and Ubiquitous Computing >An Intelligent Detection and Response Strategy to False Positives and Network Attacks: Operation of Network Quarantine Channels and Feedback Methods to IDS
【24h】

An Intelligent Detection and Response Strategy to False Positives and Network Attacks: Operation of Network Quarantine Channels and Feedback Methods to IDS

机译:误报和网络攻击的智能检测和响应策略:网络隔离通道的操作和IDS的反馈方法

获取原文

摘要

Network-based Intrusion Detection Systems (IDSs) are designed to monitor potential attacks in network infrastructures. IDSs trigger alerts of potential attacks in network security. These alerts are examined by security analysts to see if they are benign or attacks. However these alerts consist of high volumes of false positives, which are triggered by suspicious but normal, benign connections. These high volumes of false positives makes manual analysis of the alerts difficult and inefficient in real-time detection and response. In this paper we discuss briefly the significance of false positives and their impact on intrusion detection and response. Then we propose a novel approach for an efficient intelligent detection and response through the reduction of false positives. The intelligent strategy consists of technique with multiple zones for isolation and interaction with the hosts from which the packets were sent in real-time. We propose multiple feedback methods to the IDS monitor and database to indicate the status of the alerts. These innovative approaches, using NQC and feedback mechanisms enhance the capability of the IDS to detect threats and benign attacks. This is accomplished by applying adaptive rules to the alert filters and policies of the IDS network sensors.
机译:基于网络的入侵检测系统(IDS)旨在监控网络基础架构中的潜在攻击。 IDSS触发网络安全性潜在攻击的警报。通过安全分析师审查这些警报,看看它们是否是良性或攻击。然而,这些警报由高卷的误报组成,这是由可疑但正常的良性连接触发的。这些高卷的误报可以在实时检测和响应中手动分析警报困难和低效。在本文中,我们简要讨论了误报的重要性及其对入侵检测和反应的影响。然后,我们提出了一种新颖的方法,可以通过减少误报来实现高效的智能检测和响应。智能策略包括具有多个区域的技术,用于与实时发送数据包发送数据包的主机的隔离和交互。我们向IDS监视器和数据库提出多个反馈方法,以指示警报的状态。这些创新方法使用NQC和反馈机制增强了ID检测威胁和良性攻击的能力。这是通过将自适应规则应用于IDS网络传感器的警报过滤器和策略来完成的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号