首页> 外文会议>International conference on measuring technology and mechatronics automation >Reducing False Negatives in Intelligent Intrusion Detection Decision Response System
【24h】

Reducing False Negatives in Intelligent Intrusion Detection Decision Response System

机译:减少智能入侵检测决策响应系统中的错误否定

获取原文

摘要

As soon as the Intrusion Detection System (IDS) detects any suspicious or malicious activity, it will generate alarms. Unfortunately, the triggered alarms usually are accompanied with huge number of false alarms (false-positives and false-negatives) which is the key performance parameters of the IDS. The risk of false-negatives is higher than false-positives. In our previous paper, we proposed a novel intelligent intrusion detection, decision, response system (I2D2RS) with fuzzy theory, which use the two essential information times and time, of the failed login to decide automatically the attacker like an experienced system/security administrator. Though the system can reduce the false alarms perfectly, the capability of processing simultaneous multi-point attack is relatively weak, and then false-negatives will be occurred. In this paper, we employ a preprocessing module to collect the failed login information before data processing. The proposed approach changes the processing procedure from serial to parallel processing, thus eliminates the false-negatives. The efficiency of these improvements was confirmed with the experiments.
机译:一旦入侵检测系统(IDS)检测到任何可疑或恶意活动,它将产生警报。不幸的是,触发的警报通常伴随着大量的误报(假阳性和假阴性),这是ID的关键性能参数。假阴性的风险高于假阳性。在我们之前的论文中,我们提出了一种新颖的智能入侵检测,决定,响应系统(I2D2R),模糊理论,使用这两个基本信息时间和时间,失败登录以自动决定攻击者如经验丰富的系统/安全管理员。虽然系统可以完全降低误报,但加工同时多点攻击的能力相对较弱,然后将发生假否定。在本文中,我们采用预处理模块来收集数据处理之前的登录信息。所提出的方法将处理过程从串行变为并行处理,从而消除了假阴性。通过实验证实了这些改进的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号