首页> 外文期刊>Advances in Science, Technology and Engineering Systems >Building an Efficient Alert Management Model for Intrusion Detection Systems
【24h】

Building an Efficient Alert Management Model for Intrusion Detection Systems

机译:为入侵检测系统构建有效的警报管理模型

获取原文
           

摘要

This paper is an extension of work originally presented in WITS-2017 CONF. We extend our previous works by improving the Risk calculation formula, and risk assessment of an alert cluster instead of every single alert. Also, we presented the initial results of the implementation of our model based on risk assessment and alerts prioritization. The idea focuses on a new approach to estimate the risk of each alert and a cluster of alerts. This approach uses indicators such as priority, reliability and asset value as decision factors to calculate alert’s risk. The objective is to determine the impact of alerts generated by Intrusion detection system (IDS) on the security status of an information system, and also improve the detection of intrusions using snort IDS by classifying the most critical alerts by their levels of risk. Thus, only alerts that present a real threat will be displayed to the security administrator. The implementation of this approach will reduce the number of false alerts and improve the performance of the IDS.
机译:本文是对WITS-2017 CONF中最初提出的工作的扩展。我们通过改进“风险”计算公式以及对警报集群(而不是每个警报)的风险评估来扩展以前的工作。此外,我们还基于风险评估和警报优先级介绍了模型实施的初步结果。这个想法侧重于一种新的方法来估计每个警报和警报集群的风险。这种方法使用诸如优先级,可靠性和资产价值之类的指标作为决策因素来计算警报的风险。目的是确定入侵检测系统(IDS)生成的警报对信息系统的安全状态的影响,并通过将最关键的警报按风险级别进行分类,从而使用snort IDS改进入侵检测。因此,只有存在实际威胁的警报才会显示给安全管理员。此方法的实施将减少错误警报的数量并提高IDS的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号