• DocumentCode
    2120375
  • Title

    An intelligent detection and response strategy to false positives and network attacks: operation of network quarantine channels and feedback methods to IDS

  • Author

    Hooper, Emmanuel

  • Author_Institution
    Inf. Security Group, London Univ., Surrey
  • fYear
    2006
  • fDate
    29-29 June 2006
  • Lastpage
    21
  • Abstract
    Network-based intrusion detection systems (IDSs) are designed to monitor potential attacks in network infrastructures. IDSs trigger alerts of potential attacks in network security. These alerts are examined by security analysts to see if they are benign or attacks. However these alerts consist of high volumes of false positives, which are triggered by suspicious but normal, benign connections. These high volumes of false positives make manual analysis of the alerts difficult and inefficient in real-time detection and response. In this paper, we discuss briefly the significance of false positives and their impact on intrusion detection and response. Then we propose a novel approach for an efficient intelligent detection and response through the reduction of false positives. The intelligent strategy consists of technique with multiple zones for isolation and interaction with the hosts from which the packets were sent in real-time. We propose multiple feedback methods to the IDS monitor and database to indicate the status of the alerts. These innovative approaches, using NQC and feedback mechanisms enhance the capability of the IDS to detect threats and benign attacks. This is accomplished by applying adaptive rules to the alert filters and policies of the IDS network sensors
  • Keywords
    computer networks; feedback; security of data; telecommunication security; feedback; intelligent detection; network quarantine channels; network security; network-based intrusion detection systems; Adaptive filters; Conferences; Data security; Databases; Feedback; Information security; Intelligent networks; Intrusion detection; Monitoring; Pattern matching;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security, Privacy and Trust in Pervasive and Ubiquitous Computing, 2006. SecPerU 2006. Second International Workshop on
  • Conference_Location
    Lyon
  • Print_ISBN
    0-7695-2549-0
  • Type

    conf

  • DOI
    10.1109/SECPERU.2006.5
  • Filename
    1644272