SwePub
Sök i LIBRIS databas

  Utökad sökning

onr:"swepub:oai:research.chalmers.se:fe099f60-923e-43ae-91a8-f78ebc37fa9d"
 

Sökning: onr:"swepub:oai:research.chalmers.se:fe099f60-923e-43ae-91a8-f78ebc37fa9d" > A Multi-Sensor Mode...

A Multi-Sensor Model to Improve Automated Attack Detection

Almgren, Magnus, 1972 (författare)
Chalmers tekniska högskola,Chalmers University of Technology
Lindqvist, Ulf, 1970 (författare)
Jonsson, Erland, 1946 (författare)
Chalmers tekniska högskola,Chalmers University of Technology
 (creator_code:org_t)
2008
2008
Engelska.
Ingår i: 11th International Symposium, RAID 2008, Cambridge, MA, USA, September 15-17, 2008. Lecture Notes in Computer Science. - 9783540874027 ; 5230/2008, s. 291-310
  • Konferensbidrag (refereegranskat)
Abstract Ämnesord
Stäng  
  • Most intrusion detection systems available today are using a single audit source for detection, even though attacks have distinct manifestations in different parts of the system. In this paper we investigate how to use the alerts from several audit sources to improve the accuracy of the intrusion detection system (IDS). Concentrating on web server attacks, we design a theoretical model to automatically reason about alerts from different sensors, thereby also giving security operators a better understanding of possible attacks against their systems. Our model takes sensor status and capability into account, and therefore enables reasoning about the absence of expected alerts. We require an explicit model for each sensor in the system, which allows us to reason about the quality of information from each particular sensor and to resolve apparent contradictions in a set of alerts.Our model, which is built using Bayesian networks, needs some initial parameter values that can be provided by the IDS operator. We apply this model in two different scenarios for web server security. The scenarios show the importance of having a model that dynamically can adapt to local transitional traffic conditions, such as encrypted requests, when using conflicting evidence from sensors to reason about attacks.

Ämnesord

NATURVETENSKAP  -- Data- och informationsvetenskap -- Annan data- och informationsvetenskap (hsv//swe)
NATURAL SCIENCES  -- Computer and Information Sciences -- Other Computer and Information Science (hsv//eng)

Nyckelord

intrusion detection - alert reasoning

Publikations- och innehållstyp

kon (ämneskategori)
ref (ämneskategori)

Hitta via bibliotek

Till lärosätets databas

Sök utanför SwePub

Kungliga biblioteket hanterar dina personuppgifter i enlighet med EU:s dataskyddsförordning (2018), GDPR. Läs mer om hur det funkar här.
Så här hanterar KB dina uppgifter vid användning av denna tjänst.

 
pil uppåt Stäng

Kopiera och spara länken för att återkomma till aktuell vy