Alarm Reduction and Correlation in Intrusion Detection Systems

dc.contributor.authorBurbeck, Kalle
dc.contributor.authorBurschka, Stefan
dc.contributor.authorChyssler, Tobias
dc.contributor.authorLingvall, Tomas
dc.contributor.authorSemling, Michael
dc.date.accessioned2006-08-16T12:09:19Z
dc.date.available2006-08-16T12:09:19Z
dc.date.issued2004-07
dc.description.abstractLarge Critical Complex Infrastructures are increasingly dependent on IP networks. Reliability by redundancy and tolerance are an imperative for such dependable networks. In order to achieve the desired reliability, the detection of faults, misuse, and attacks is essential. This can be achieved by applying methods of intrusion detection. However, in large systems, these methods produce an uncontrollable vast amount of data which overwhelms human operators. This paper studies the role of alarm reduction and correlation in existing networks for building more intelligent safeguards that support and complement the decisions by the operator. We present an architecture that incorporates Intrusion Detection Systems as sensors, and provides quantitatively and qualitatively improved alarms to the human operator. Alarm reduction via static and adaptive filtering, aggregation, and correlation is demonstrated using realistic data from sensors such as Snort, Samhain, and Syslog.en
dc.format.extent1996587 bytes
dc.format.mimetypeapplication/pdf
dc.identifier.citationTobias Chyssler, Stefan Burschka, Michael Semling, Tomas Lingvall, Kalle Burbeck: Alarm Reduction and Correlation in Intrusion Detection Systems. In Flegel, U.; Meier, M. (Eds.): Proc. of the International GI Workshop on Detection of Intrusions and Malware & Vulnerability Assessment, number P-46 in Lecture Notes in Informatics, pp. 9-24, Dortmund, Germany, July 2004, Köllen Verlag; ISBN 3-88579-365-X.de
dc.identifier.urihttp://hdl.handle.net/2003/22771
dc.identifier.urihttp://dx.doi.org/10.17877/DE290R-2012
dc.language.isoen
dc.publisherGesellschaft für Informatikde
dc.relation.ispartofDIMVA 2004, July 6-7, Dortmund, Germanyen
dc.relation.ispartofseriesLecture Notes in Informatics;P-46en
dc.subjectalarm correlationen
dc.subjectalarm reductionen
dc.subjectintrusion detectionen
dc.subject.ddc004
dc.titleAlarm Reduction and Correlation in Intrusion Detection Systemsen
dc.typeTextde
dc.type.publicationtypeconferenceObjecten
dcterms.accessRightsopen access

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
DIMVA2004-Chyssler_et_al.pdf
Size:
1.9 MB
Format:
Adobe Portable Document Format
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.91 KB
Format:
Item-specific license agreed upon to submission
Description:

Collections