...
首页> 外文期刊>Journal of applied non-classical logics >An alert correlation approach based on security operator's knowledge and preferences
【24h】

An alert correlation approach based on security operator's knowledge and preferences

机译:基于安全操作员的知识和偏好的警报关联方法

获取原文
获取原文并翻译 | 示例
           

摘要

One of the major problems of intrusion detection concerns the large amount of alerts that intrusion detection systems (IDS) produce. Security operator who analyzes alerts and takes decisions, is often submerged by the high number of alerts to analyze. In this paper, we present a new alert correlation approach based on knowledge and preferences of security operators. This approach, which is complementary to existing ones, allows to rank-order produced alerts on the basis of a security operator knowledge about the system, used IDS and his preferences about alerts that he wants to analyze or to ignore. Our approach is based on the development of a new non-classical logic for representing preferences, called FO-MQCL (First Order - Minimal Qualitative Choice Logic). Our logic extends a fragment of the first order logic by adding a new logical connective. The general idea is to present only alerts that fully fit security operator's preferences and knowledge. And if needed, less preferred alerts can also be presented.
机译:入侵检测的主要问题之一涉及入侵检测系统(IDS)产生大量警报。分析警报并做出决策的安全操作员通常被大量要分析的警报所淹没。在本文中,我们提出了一种基于安全操作员的知识和偏好的新的警报关联方法。这种方法是对现有警报的补充,它允许根据安全操作员对系统,使用过的IDS以及他希望分析或忽略的警报偏好的知识,对生成的警报进行排序。我们的方法基于一种新的表示偏好的非经典逻辑,称为FO-MQCL(一阶-最小定性选择逻辑)。我们的逻辑通过添加新的逻辑连接词来扩展一阶逻辑的片段。一般想法是仅显示完全符合安全操作员的偏好和知识的警报。并且,如果需要,还可以显示不太受欢迎的警报。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号