首页> 外文期刊>IEICE Transactions on Information and Systems >Filtering False Positives Based on Server-Side Behaviors
【24h】

Filtering False Positives Based on Server-Side Behaviors

机译:基于服务器端行为过滤误报

获取原文
获取原文并翻译 | 示例
       

摘要

Reducing the rate of false positives is of vital importance in enhancing the usefulness of signature-based network intrusion detection systems (NIDSs). To reduce the number of false positives, a network administrator must thoroughly investigate a lengthy list of signatures and carefully disable the ones that detect attacks that are not harmful to the administrator's environment. This is a daunting task; if some signatures are disabled by mistake, the NIDS fails to detect critical remote attacks. We designed a NIDS, TrueAlarm, to reduce the rate of false positives. Conventional NIDSs alert administrators that a malicious message has been detected, regardless of whether the message actually attempts to compromise the protected server. In contrast, TrueAlarm delays the alert until it has confirmed that an attempt has been made. The TrueAlarm NIDS cooperates with a server-side monitor that observes the protected server's behavior. TrueAlarm only alerts administrators when a server-side monitor has detected deviant server behavior that must have been caused by a message detected by a NIDS. Our experimental results revealed that TrueAlarm reduces the rate of false positives. Using actual network traffic collected over 14 days, TrueAlarm produced 46 false positives, while Snort, a conventional NIDS, produced 818.
机译:减少误报率对于增强基于签名的网络入侵检测系统(NIDS)的有效性至关重要。为了减少误报的数量,网络管理员必须彻底调查冗长的签名列表,并仔细禁用那些检测对管理员环境无害的攻击的签名。这是一项艰巨的任务。如果错误地禁用了某些签名,则NIDS无法检测到严重的远程攻击。我们设计了一种NIDS TrueAlarm,以减少误报率。常规NIDS会警告管理员已检测到恶意消息,无论该消息是否实际上试图危害受保护的服务器。相反,TrueAlarm延迟警报,直到确认进行了尝试。 TrueAlarm NIDS与服务器端监视器配合使用,该监视器可观察受保护服务器的行为。 TrueAlarm仅在服务器端监视器检测到必须由NIDS检测到的消息引起的异常服务器行为时才警告管理员。我们的实验结果表明,TrueAlarm可以降低误报率。使用过去14天收集的实际网络流量,TrueAlarm产生了46次误报,而传统的NIDS Snort产生了818次。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号