Logo image
在聯防系統下為Hyper-alert Correlation建立攻擊警訊的相互關聯性
Thesis

在聯防系統下為Hyper-alert Correlation建立攻擊警訊的相互關聯性

宋奕儒
Masters, National Tsing Hua University
2002

Abstract

入侵偵測 intrusion detectionalert correlation
In response to the attacks against internet networks, intrusion detection systems are deployed for this purpose. But current intrusion detection systems generate too many false alerts. The raising alerts are too elementary and do not accurate enough to be managed by a security administrator. Several alert correlation techniques have been proposed to solve this problem, such as hyper-alert correlation. The hyper-alert correlation takes advantage of the prerequisites and consequences of the attack to correlate the related alerts together. But the performance of this approach highly depends on the quality of the modeling of attacks. On the other hand, with growing of the network attacks, specifying the relationship for alert correlation would be quite complex and tedious task to perform mutually. This thesis presents a practical technique to address this issue for hyper-alert correlation. On the basis of the attack signatures and the hyper-alert types defined in hyper-alert correlation, the proposed approach constructs alert relationship automatically. Furthermore, to take the various kinds of attacks into consideration, some of the relationships between attacks may be neglected. At this time, fine tuning the relationship by human user can efficiently deal with the above problem.

Metrics

1 Record Views

Details

Logo image