Alarm reduction and correlation in defence of IP networks

被引:17
作者
Chyssler, T [1 ]
Nadjm-Tehrani, S [1 ]
Burschka, S [1 ]
Burbeck, K [1 ]
机构
[1] Linkoping Univ, Dept Comp & Informat Sci, Linkoping, Sweden
来源
THIRTEENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS | 2004年
关键词
D O I
10.1109/ENABL.2004.7
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Society's critical infrastructures are increasingly dependent on IP networks. Intrusion detection and tolerance within data networks is therefore imperative for dependability in other domains such as telecommunications and future energy management networks. Today's data networks are protected by human operators that are exceedingly overwhelmed by the massive information overload through false alarm rates of the protection mechanisms. This paper studies the role of alarm reduction and correlation in supporting the security administrator in an enterprise network. We present an architecture that incorporates intrusion detection systems as sensors, and provides improved alarm data to the human operator or to automated actuators. Alarm reduction and correlation via static and adaptive filtering, normalisation, and aggregation is demonstrated on the output from three sensors (Snort, Samhain and Syslog) used in a telecom test network.
引用
收藏
页码:229 / 234
页数:6
相关论文
共 17 条
[1]  
[Anonymous], 2002, P 8 ACM SIGKDD INT C, DOI DOI 10.1145/775047.775101
[2]  
[Anonymous], INTRO NEURAL NETWORK
[3]  
Burbeck K, 2003, P WORK PROGR SESS 24
[4]  
CHYSSLER T, 2003, LITHIDAEX03067SE LIN
[5]  
Cuppens F, 2002, P IEEE S SECUR PRIV, P202, DOI 10.1109/SECPRI.2002.1004372
[6]  
Debar H., 2001, P 4 INT S REC ADV IN, P85, DOI DOI 10.1007/3-540-45474-8_
[7]  
Devroye L., 1996, A probabilistic theory of pattern recognition
[8]  
Heckerman D., 1995, MSRTR9506
[9]   Intrusion and intrusion detection [J].
John McHugh .
International Journal of Information Security, 2001, 1 (1) :14-35
[10]  
Morin B, 2003, LECT NOTES COMPUT SC, V2820, P94