Autor(en): Burbeck, Kalle
Burschka, Stefan
Chyssler, Tobias
Lingvall, Tomas
Semling, Michael
Titel: Alarm Reduction and Correlation in Intrusion Detection Systems
Sprache (ISO): en
Zusammenfassung: Large Critical Complex Infrastructures are increasingly dependent on IP networks. Reliability by redundancy and tolerance are an imperative for such dependable networks. In order to achieve the desired reliability, the detection of faults, misuse, and attacks is essential. This can be achieved by applying methods of intrusion detection. However, in large systems, these methods produce an uncontrollable vast amount of data which overwhelms human operators. This paper studies the role of alarm reduction and correlation in existing networks for building more intelligent safeguards that support and complement the decisions by the operator. We present an architecture that incorporates Intrusion Detection Systems as sensors, and provides quantitatively and qualitatively improved alarms to the human operator. Alarm reduction via static and adaptive filtering, aggregation, and correlation is demonstrated using realistic data from sensors such as Snort, Samhain, and Syslog.
Schlagwörter: alarm correlation
alarm reduction
intrusion detection
URI: http://hdl.handle.net/2003/22771
http://dx.doi.org/10.17877/DE290R-2012
Erscheinungsdatum: 2004-07
Provinienz: Gesellschaft für Informatik
Zitierform: Tobias Chyssler, Stefan Burschka, Michael Semling, Tomas Lingvall, Kalle Burbeck: Alarm Reduction and Correlation in Intrusion Detection Systems. In Flegel, U.; Meier, M. (Eds.): Proc. of the International GI Workshop on Detection of Intrusions and Malware & Vulnerability Assessment, number P-46 in Lecture Notes in Informatics, pp. 9-24, Dortmund, Germany, July 2004, Köllen Verlag; ISBN 3-88579-365-X.
Ist Teil von: DIMVA 2004, July 6-7, Dortmund, Germany
Enthalten in den Sammlungen:Papers

Dateien zu dieser Ressource:
Datei Beschreibung GrößeFormat 
DIMVA2004-Chyssler_et_al.pdf1.95 MBAdobe PDFÖffnen/Anzeigen


Diese Ressource ist urheberrechtlich geschützt.



Diese Ressource ist urheberrechtlich geschützt. rightsstatements.org