Εμφάνιση απλής εγγραφής

dc.creatorSpathoulas, G. P.en
dc.creatorKatsikas, S. K.en
dc.date.accessioned2015-11-23T10:48:09Z
dc.date.available2015-11-23T10:48:09Z
dc.date.issued2013
dc.identifier10.1016/j.cose.2013.03.005
dc.identifier.issn0167-4048
dc.identifier.urihttp://hdl.handle.net/11615/33256
dc.description.abstractIntrusion detection systems (IDS) are among the most common countermeasures against network attacks. In order to improve the alerts obtained from them, various methods of post-processing have been proposed. These methods usually try to alleviate specific drawbacks of intrusion detection. We propose a system that is a post-processing solution. The input of our system is a set of multiple IDS sensors alert sets. Each set's alerts are aggregated in order to improve their quality, before multiple alert sets merge into one general alert set. Then, a low clustering procedure allows the system to hypothesize about missed security events and to create relevant alerts. The main clustering phase comes next, before the final step, in which a clusters graph is generated to produce a high level presentation of the security events. The system has been tested using the DARPA 2000 dataset, as well as a live network dataset, and has produced satisfactory results. (c) 2013 Elsevier Ltd. All rights reserved.en
dc.sourceComputers & Securityen
dc.source.uri<Go to ISI>://WOS:000323360000014
dc.subjectIntrusion detection systemsen
dc.subjectAggregationen
dc.subjectCorrelationen
dc.subjectPredictionen
dc.subjectVisualizationen
dc.subjectINTRUSION DETECTIONen
dc.subjectMOBILE-VISUALIZATIONen
dc.subjectComputer Science, Information Systemsen
dc.titleEnhancing IDS performance through comprehensive alert post-processingen
dc.typejournalArticleen


Αρχεία σε αυτό το τεκμήριο

ΑρχείαΜέγεθοςΤύποςΠροβολή

Δεν υπάρχουν αρχεία που να σχετίζονται με αυτό το τεκμήριο.

Αυτό το τεκμήριο εμφανίζεται στις ακόλουθες συλλογές

Εμφάνιση απλής εγγραφής