...
首页> 外文期刊>International Journal of Information Security >ISM-AC: an immune security model based on alert correlation and software-defined networking
【24h】

ISM-AC: an immune security model based on alert correlation and software-defined networking

机译:ISM-AC: an immune security model based on alert correlation and software-defined networking

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Anomaly-based detection techniques have a high number of false positives, which degrades the detection performance. To address this issue, we propose a distributed intrusion detection system, named ISM-AC, based on anomaly detection using artificial immune system and attack graph correlation. To analyze network traffic, we use negative selection, clonal selection, and immune network algorithms to implement an agent-based detection system. ISM-AC leverages the programmability of software-defined networking to reduce the false positive rate. Our findings show that ISM-AC achieves better detection performance for denial of service, user to root, remote to local, and probe attack classes. Alert correlation plays a key role in this achievement.

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号