首页> 外文期刊>Engineering Applications of Artificial Intelligence >Alarm clustering for intrusion detection systems in computer networks
【24h】

Alarm clustering for intrusion detection systems in computer networks

机译:计算机网络中入侵检测系统的警报群集

获取原文
获取原文并翻译 | 示例
           

摘要

Until recently, network administrators manually arranged alarms produced by intrusion detection systems (IDS) to attain a high-level description of cyberattacks. As the number of alarms is increasingly growing, automatic tools for alarm clustering have been proposed to provide such a high-level description of the attack scenarios. In addition, it has been shown that effective threat analysis requires the fusion of different sources of information, such as different IDS. This paper proposes a new strategy to perform alarm clustering which produces unified descriptions of attacks from alarms produced by multiple IDS. In order to be effective, the proposed alarm clustering system takes into account two characteristics of IDS: (ⅰ) for a given attack, different sensors may produce a number of alarms reporting different attack descriptions; and (ⅱ) a certain attack description may be produced by the IDS in response to different types of attack. Experimental results show that the high-level alarms produced by the alarm clustering module effectively summarize the attacks, drastically reducing the volume of alarms presented to the administrator. In addition, these high-level alarms can be used as the base to perform further higher-level threat analysis.
机译:直到最近,网络管理员还手动安排了入侵检测系统(IDS)发出的警报,以获取对网络攻击的高级描述。随着警报数量的不断增长,已经提出了用于警报群集的自动工具来提供对攻击场景的如此高级描述。另外,已经表明,有效的威胁分析需要融合不同的信息源,例如不同的IDS。本文提出了一种执行警报聚类的新策略,该策略可以根据多个IDS产生的警报对攻击进行统一描述。为了有效,建议的警报聚类系统考虑了IDS的两个特征:(ⅰ)对于给定的攻击,不同的传感器可能会产生许多报告不同攻击描述的警报; (ⅱ)IDS可能会针对不同类型的攻击生成特定的攻击描述。实验结果表明,警报集群模块生成的高级警报可以有效地汇总攻击,从而大大减少了向管理员显示的警报数量。此外,这些高级警报可以用作执行进一步的高级威胁分析的基础。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号