节点文献
基于报警管理的分布式入侵检测系统模型
Distributed intrusion detection framework based on alert management
【Author】 Zhang Jie Li Jun Fu Huanhuan (School of Information Science & Technology,Nanjing University of Aeronautics and Astronautics,Nanjing 210016)
【机构】 南京航空航天大学信息科学与技术学院;
【摘要】 为了有效消除分布式入侵检测系统中报警冗余问题,本文提出了一个入侵报警管理系统模型,包括对报警格式的统一、验证、聚合和置信度学习。该模型采用基于属性相似度的报警聚合方法在线对报警进行分析处理;并结合事件的前因后果关联法离线对报警数据进行多步骤的攻击过程分析;最后通过报警置信度对报警信息进行进一步的过滤。相比现有的IDS,该模型的结构更加完整,能够更容易地发现攻击并有效降低误报率。
【Abstract】 In order to effectively eliminate the redundancy of the alert data in distributed intrusion detection system,this paper proposed a new intrusion detection alert management framework,including the unity,verification,aggregation and the confidence learning of the alert data.An algorithm based on similarity calculating was used to analysis the alerts on - line;combined with the correlation method based on prerequisites and consequences to recognize multi steps attack;then learn the confidence metric to filter alerts further.Compared to existing IDS,this framework is more integrated and easier to find attacks with lower false positive rate.
【Key words】 Distributed Intrusion Detection; Alert Aggregation; Similarity; Confidence;
- 【会议录名称】 中国电子学会第十七届信息论学术年会论文集
- 【会议名称】中国电子学会第十七届信息论学术年会
- 【会议时间】2010-10
- 【会议地点】中国陕西西安
- 【分类号】TP393.08
- 【主办单位】中国电子学会信息论分会