DocumentCode :
690511
Title :
A Comparative Study of Alert Correlations for Intrusion Detection
Author :
Leau Yu Beng ; Ramadass, Sureswaran ; Manickam, Selvakumar ; Tan Soo Fun
Author_Institution :
Nat. Adv. IPv6 Centre (Nav6), Univ. Sains Malaysia, Minden, Malaysia
fYear :
2013
fDate :
23-24 Dec. 2013
Firstpage :
85
Lastpage :
88
Abstract :
The prevalent use of computer applications and communication technologies has rising the numbers of network intrusion attempts. These malicious attempts including hacking, botnets and works are pushing organization networks to a risky atmosphere where the intruder tries to compromise the confidentiality, integrity and availability of resources. In order to detect these malicious activities, Intrusion Detection Systems (IDSs) have been widely deployed in corporate networks. IDSs play an important role in monitoring traffic behaviors in a computer network, identifying the anomalous activity and notifying the security analyst with current network status. Unfortunately, one of the IDSs´ drawbacks is they produce a large number of false positives and non-relevant positives alerts that could overwhelm the security analyst. Therefore, the process of analyzing alerts in order to provide a more synthetic and high-level view of the attempted intrusions is needed. This process is called Alert Correlation. In this paper, we present commonly used alert correlation approaches and highlight their advantages and disadvantages from various perspectives. Subsequently, we summarize some current alert correlation models with their alert correlation approach.
Keywords :
security of data; IDS; alert correlation models; intrusion detection systems; malicious attempts; network intrusion attempts; Computational modeling; Computers; Correlation; Data mining; Internet; Intrusion detection; Alert Correlatios; Anomaly Detection; Intrusion Detection System; Misuse Detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Advanced Computer Science Applications and Technologies (ACSAT), 2013 International Conference on
Conference_Location :
Kuching
Type :
conf
DOI :
10.1109/ACSAT.2013.24
Filename :
6836553
Link To Document :
بازگشت