...
首页> 外文期刊>Computers & Security >Real-time analysis of intrusion detection alerts via correlation
【24h】

Real-time analysis of intrusion detection alerts via correlation

机译:通过相关性实时分析入侵检测警报

获取原文
获取原文并翻译 | 示例

摘要

With the growing deployment of networks and the Internet, the importance of network security has increased. Recently, however, systems that detect intrusions, which are important in security countermeasures, have been unable to provide proper analysis or an effective defense mechanism. Instead, they have overwhelmed human operators with a large volume of intrusion detection alerts. This paper presents a fast and efficient system for analyzing alerts. Our system basically depends on the probabilistic correlation. However, we enhance the probabilistic correlation by applying more systematically defined similarity functions and also present a new correlation component that is absent in other correlation models. The system can produce meaningful information by aggregating and correlating the large volume of alerts and can detect Large-scale attacks such as distributed denial of service (DDoS) in early stage. We measured the processing rate of each elementary component and carried out a scenario-based test in order to analyze the efficiency of our system. Although the system is still imperfect, we were able to reduce the numerous redundant alerts 5.5% of the original volume without distorting the meaning through two-phase reduction. This ability reduces the management overhead drastically and makes the analysis and correlation easy. Moreover, we were able to construct attack scenarios for multistep attacks and detect large-scale attacks in real time. (C) 2005 Elsevier Ltd. All rights reserved.
机译:随着网络和Internet的部署不断增长,网络安全的重要性日益提高。但是,近来,在安全对策中很重要的检测入侵的系统无法提供适当的分析或有效的防御机制。取而代之的是,它们以大量的入侵检测警报使人类操作员不知所措。本文提出了一种快速有效的警报分析系统。我们的系统基本上取决于概率相关性。但是,我们通过应用更系统地定义的相似度函数来增强概率相关性,并且还提出了其他相关性模型中不存在的新的相关性组件。该系统可以通过聚集和关联大量警报来产生有意义的信息,并且可以在早期检测到大规模攻击,例如分布式拒绝服务(DDoS)。我们测量了每个基本组件的处理速度,并进行了基于场景的测试,以分析系统的效率。尽管系统仍然不完美,但我们能够将大量冗余警报减少为原始音量的5.5%,而不会通过两阶段减少来扭曲含义。此功能大大减少了管理开销,并使分析和关联变得容易。此外,我们能够构造用于多步攻击的攻击方案并实时检测大规模攻击。 (C)2005 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号