首页> 外文会议>International Conference on Network and System Security >A Flexible and Efficient Alert Correlation Platform for Distributed IDS
【24h】

A Flexible and Efficient Alert Correlation Platform for Distributed IDS

机译:用于分布式ID的灵活高效的警报相关平台

获取原文

摘要

Intrusion Detection Systems (IDS) have been widely deployed in practice for detecting malicious behavior on network communication and hosts. The problem of false-positive alerts is a popular existing problem for most of IDS approaches. The solution to address this problem is correlation and clustering of alerts. To meet the practical requirements, this process needs to be finished as soon as possible, which is a challenging task as the amount of alerts produced in large scale deployments of distributed IDS is significantly high. We identify the data storage and processing algorithms to be the most important factors influencing the performance of clustering and correlation. We propose and implement the utilization of memory-supported algorithms and a column-oriented database for correlation and clustering in an extensible IDS correlation platform. The utilization of the column-oriented database, an In-Memory Alert Storage, and memory-based index tables leads to significant improvements on the performance. Different types of correlation modules can be integrated and compared on this platform. A plugin concept for Receivers provides flexible integration of various sensors and additional IDS management systems. The platform can be distributed over multiple processing units to share memory and processing power. A standardized interface is designed to provide a unified view of result reports for end users. The efficiency of the proposed platform is tested by practical experiments with several alert storage approaches, different simple algorithms, as well as local and distributed deployment.
机译:在实践中,入侵检测系统(IDS)已被广泛部署,以检测网络通信和主机上的恶意行为。对于大多数ID方法,假正警报的问题是一个流行的现有问题。解决此问题的解决方案是相关性和群集警报。为满足实际要求,此过程需要尽快完成,这是一个具有挑战性的任务,因为在大规模部署的分布式IDS中产生的警报量显着高。我们将数据存储和处理算法确定为影响聚类和相关性能的最重要因素。我们提出并实施了利用内存支持的算法和面向列的数据库,以便在可扩展ID相关平台中的相关和聚类。利用面向列的数据库,内存内警报存储和基于内存的索引表,导致对性能的显着改进。可以在该平台上集成并比较不同类型的相关模块。接收器的插件概念提供各种传感器和其他IDS管理系统的灵活集成。该平台可以在多个处理单元上分布以共享存储器和处理电源。标准化接口旨在为最终用户提供统一的结果报告视图。所提出的平台的效率是通过具有多个警报储存方法,不同简单算法以及本地和分布式部署的实际实验来测试的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号