首页> 外文会议>Modeling approaches and algorithms for advanced computer applications >A New Approach for QCL-Based Alert Correlation Process
【24h】

A New Approach for QCL-Based Alert Correlation Process

机译:基于QCL的警报关联过程的新方法

获取原文
获取原文并翻译 | 示例

摘要

Intrusion Detection Systems (IDS) are very important tools for network monitoring. However, they often produce a large quantity of alerts. The security operator who analyses IDS alerts is quickly overwhelmed. Alert correlation is a process applied to the IDS alerts in order to reduce their number. In this paper, we propose a new approach for logical based alert correlation which integrates the security operator's knowledge and preferences in order to present to him only the most suitable alerts. The representation and the reasoning on these knowledge and preferences are done using a new logic called Instantiated First Order Qualitative Choice Logic (IFO-QCL). Our modeling shows an alert as an interpretation which allows us to have an efficient algorithm that performs the correlation process in a polynomial time. Experimental results are achieved on data collected from a real system monitoring. The result is a set of stratified alerts satisfying the operators criteria.
机译:入侵检测系统(IDS)是用于网络监视的非常重要的工具。但是,它们通常会产生大量警报。分析IDS警报的安全操作员很快就不知所措。警报关联是应用于IDS警报以减少其数量的过程。在本文中,我们提出了一种用于基于逻辑的警报关联的新方法,该方法集成了安全操作员的知识和偏好,以便仅向其提供最合适的警报。这些知识和偏好的表示以及推理是使用称为“实例化一阶定性选择逻辑”(IFO-QCL)的新逻辑完成的。我们的建模将警报显示为一种解释,它使我们可以使用有效的算法在多项式时间内执行相关过程。从实际系统监控中收集的数据获得了实验结果。结果是满足操作员标准的一组分层警报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号