Εμφάνιση απλής εγγραφής

dc.creatorSpathoulas, G. P.en
dc.creatorKatsikas, S. K.en
dc.date.accessioned2015-11-23T10:48:09Z
dc.date.available2015-11-23T10:48:09Z
dc.date.issued2010
dc.identifier10.1016/j.cose.2009.07.008
dc.identifier.issn0167-4048
dc.identifier.urihttp://hdl.handle.net/11615/33255
dc.description.abstractA post-processing filter is proposed to reduce false positives in network-based intrusion detection systems. The filter comprises three components, each one of which is based upon statistical properties of the input alert set. Special characteristics of alerts corresponding to true attacks are exploited. These alerts may be observed in batches, which contain similarities in the source or destination IPs, or they may produce abnormalities in the distribution of alerts of the same signature. False alerts can be recognized by the frequency with which their signature triggers false positives. The filter architecture and design are discussed. Evaluation results performed using the DARPA 1999 dataset indicate that the proposed approach can significantly reduce the number and percentage of false positives produced by Snort (c) (Roesch, 1999). Our filter limited false positives by a percentage up to 75%. (C) 2009 Elsevier Ltd. All rights reserved.en
dc.sourceComputers & Securityen
dc.source.uri<Go to ISI>://WOS:000272862400004
dc.subjectIntrusion detection systemsen
dc.subjectFalse alarmsen
dc.subjectFilteren
dc.subjectSnorten
dc.subjectAlarms'en
dc.subjectdistributionen
dc.subjectComputer Science, Information Systemsen
dc.titleReducing false positives in intrusion detection systemsen
dc.typejournalArticleen


Αρχεία σε αυτό το τεκμήριο

ΑρχείαΜέγεθοςΤύποςΠροβολή

Δεν υπάρχουν αρχεία που να σχετίζονται με αυτό το τεκμήριο.

Αυτό το τεκμήριο εμφανίζεται στις ακόλουθες συλλογές

Εμφάνιση απλής εγγραφής