首页> 外文期刊>Concurrency and computation: practice and experience >A novel lightweight cache-based scheme for large-scale intrusion alert fusion
【24h】

A novel lightweight cache-based scheme for large-scale intrusion alert fusion

机译:一种新颖的基于轻量级缓存的大规模入侵警报融合方案

获取原文
获取原文并翻译 | 示例

摘要

In this paper, we present some practical experiences on implementing an alert fusion mechanism from our project. After investigation on most of the existing alert fusion systems, we found the current body of work alternatively weighed down in the mire of insecure design or rarely deployed because of their complexity. As confirmed by our experimental analysis, unsuitable mechanisms could easily be submerged by an abundance of useless alerts. Even with the use of methods that achieve a high fusion rate and low false positives, attack is also possible. To find the solution, we carried out analysis on a series of alerts generated by well-known datasets as well as realistic alerts from the Australian Honey-Pot. One important finding is that one alert has more than an 85% chance of being fused in the following five alerts. Of particular importance is our design of a novel lightweight Cache-based Alert Fusion Scheme, called CAFS. CAFS has the capacity to not only reduce the quantity of useless alerts generated by intrusion detection system, but also enhance the accuracy of alerts, therefore greatly reducing the cost of fusion processing. We also present reasonable and practical specifications for the target-oriented fusion policy that provides a quality guarantee on alert fusion, and as a result seamlessly satisfies the process of successive correlation. Our experiments compared CAFS with traditional centralized fusion. The results showed that the CAFS easily attained the desired level of simple, counter-escapable alert fusion design. Furthermore, as a lightweight scheme, CAFS can easily be deployed and excel in a large amount of alert fusions, which go towards improving the usability of system resources. To the best of our knowledge, our work is a practical exploration in addressing problems from the academic point of view.
机译:在本文中,我们提供了一些从项目中实施警报融合机制的实践经验。在对大多数现有的警报融合系统进行调查之后,我们发现当前的工作沉迷于不安全设计的泥潭或由于其复杂性而很少部署。正如我们的实验分析所证实的那样,不适当的机制很容易被大量无用的警报淹没。即使使用实现高融合率和低误报的方法,攻击也是可能的。为了找到解决方案,我们对由知名数据集生成的一系列警报以及澳大利亚蜜罐中的现实警报进行了分析。一个重要发现是,在以下五个警报中,一个警报被融合的可能性大于85%。尤其重要的是,我们设计了一种新颖的轻量级基于缓存的警报融合方案,称为CAFS。 CAFS不仅可以减少入侵检测系统生成的无用警报的数量,还可以提高警报的准确性,从而大大降低了融合处理的成本。我们还针对面向目标的融合策略提出了合理而实用的规范,该规范为警报融合提供了质量保证,从而无缝地满足了连续相关的过程。我们的实验将CAFS与传统的集中式融合进行了比较。结果表明,CAFS可以轻松达到所需的简单,可逆转的警报融合设计水平。此外,作为轻量级方案,CAFS可以轻松部署并在大量警报融合方面表现出色,这有助于提高系统资源的可用性。就我们所知,我们的工作是从学术角度解决问题的实践探索。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号