首页> 外文期刊>International Journal of Computer Science and Security >Managing Intrusion Detection Alerts Using Support Vector Machines
【24h】

Managing Intrusion Detection Alerts Using Support Vector Machines

机译:使用支持向量机管理入侵检测警报

获取原文
           

摘要

In the computer network world Intrusion detection systems (IDS) are used to identify attacks against computer systems. They produce security alerts when an attack is done by an intruder. Since IDSs generate high amount of security alerts, analyzing them are time consuming and error prone. To solve this problem IDS alert management techniques are introduced. They manage generated alerts and handle true positive and false positive alerts. In this paper a new alert management system is presented. It uses support vector machine (SVM) as a core component of the system that classify generated alerts. The proposed algorithm achieves high accurate result in false positives reduction and identifying type of true positives. Because of low classification time per each alert, the system also could be used in active alert management systems.
机译:在计算机网络世界中,入侵检测系统(IDS)用于识别针对计算机系统的攻击。当入侵者进行攻击时,它们会发出安全警报。由于IDS会生成大量的安全警报,因此对其进行分析既耗时又容易出错。为了解决这个问题,引入了IDS警报管理技术。他们管理生成的警报并处理真实肯定和错误肯定警报。本文提出了一种新的警报管理系统。它使用支持向量机(SVM)作为系统的核心组件,对生成的警报进行分类。所提出的算法在减少误报和识别出真阳性的类型方面取得了很高的准确率。由于每个警报的分类时间很短,因此该系统还可用于主动警报管理系统。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号