首页> 外文期刊>Future generation computer systems >A comprehensive vulnerability based alert management approach for large networks
【24h】

A comprehensive vulnerability based alert management approach for large networks

机译:大型网络的基于漏洞的全面警报管理方法

获取原文
获取原文并翻译 | 示例

摘要

Traditional Intrusion Detection Systems (IDSs) are known for generating large volumes of alerts despite all the progress made over the last few years. The analysis of a huge number of raw alerts from large networks is often time consuming and labour intensive because the relevant alerts are usually buried under heaps of irrelevant alerts. Vulnerability based alert management approaches have received considerable attention and appear extremely promising in improving the quality of alerts. They filter out any alert that does not have a corresponding vulnerability hence enabling the analysts to focus on the important alerts. However, the existing vulnerability based approaches are still at the preliminary stage and there are some research gaps that need to be addressed. The act of validating alerts may not guarantee alerts of high quality because the validated alerts may contain huge volumes of redundant and isolated alerts. The validated alerts too lack additional information needed to enhance their meaning and semantic. In addition, the use of outdated vulnerability data may lead to poor alert verification. In this paper, we propose a fast and efficient vulnerability based approach that addresses the above issues. The proposed approach combines several known techniques in a comprehensive alert management framework in order to offer a novel solution. Our approach is effective and yields superior results in terms of improving the quality of alerts.
机译:尽管过去几年取得了所有进展,但传统的入侵检测系统(IDS)仍会生成大量警报,这一点众所周知。对大型网络中大量原始警报的分析通常很耗时且费力,因为相关警报通常埋在不相关警报的堆中。基于漏洞的警报管理方法已受到相当多的关注,并且在提高警报质量方面显得很有前途。它们可以过滤出没有相应漏洞的所有警报,从而使分析人员可以将精力集中在重要警报上。但是,现有的基于漏洞的方法仍处于初期阶段,存在一些研究空白需要解决。验证警报的行为可能无法保证警报的质量,因为经过验证的警报可能包含大量的冗余警报和隔离警报。经过验证的警报也缺少增强其含义和语义所需的其他信息。此外,使用过时的漏洞数据可能会导致不良的警报验证。在本文中,我们提出了一种快速有效的基于漏洞的方法来解决上述问题。所提出的方法在全面的警报管理框架中结合了几种已知技术,以提供一种新颖的解决方案。我们的方法是有效的,并且在提高警报质量方面产生了卓越的结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号