GI LogoGI Logo
  • Anmelden
Digitale Bibliothek
    • Gesamter Bestand

      • Bereiche & Sammlungen
      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
    • Diese Sammlung

      • Titel
      • Autor
      • Erscheinungsdatum
      • Schlagwort
Digital Bibliothek der Gesellschaft für Informatik e.V.
GI-DL
    • English
    • Deutsch
  • Deutsch 
    • English
    • Deutsch
Dokumentanzeige 
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • P046 - DIMVA 2004 - Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop,
  • Dokumentanzeige
JavaScript is disabled for your browser. Some features of this site may not work without it.
  •   Startseite
  • Lecture Notes in Informatics
  • Proceedings
  • P046 - DIMVA 2004 - Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop,
  • Dokumentanzeige

Alarm reduction and correlation in intrusion detection systems

Autor(en):
Chyssler, Tobias [DBLP] ;
Burschka, Stefan [DBLP] ;
Semling, Michael [DBLP] ;
Lingvall, Tomas [DBLP] ;
Burbeck, Kalle [DBLP]
Zusammenfassung
Large Critical Complex Infrastructures are increasingly dependent on IP networks. Reliability by redundancy and tolerance are an imperative for such dependable networks. In order to achieve the desired reliability, the detection of faults, misuse, and attacks is essential. This can be achieved by applying methods of intrusion detection. However, in large systems, these methods produce an uncontrollable vast amount of data which overwhelms human operators. This paper studies the role of alarm reduction and correlation in existing networks for building more intelligent safeguards that support and complement the decisions by the operator. We present an architecture that incorporates Intrusion Detection Systems as sensors, and provides quantitatively and qualitatively improved alarms to the human operator. Alarm reduction via static and adaptive filtering, aggregation, and correlation is demonstrated using realistic data from sensors such as Snort, Samhain, and Syslog.
  • Vollständige Referenz
  • BibTeX
Chyssler, T., Burschka, S., Semling, M., Lingvall, T. & Burbeck, K., (2004). Alarm reduction and correlation in intrusion detection systems. In: Flegel, U. & Meier, M. (Hrsg.), Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004. Bonn: Gesellschaft für Informatik e.V.. (S. 9-24).
@inproceedings{mci/Chyssler2004,
author = {Chyssler, Tobias AND Burschka, Stefan AND Semling, Michael AND Lingvall, Tomas AND Burbeck, Kalle},
title = {Alarm reduction and correlation in intrusion detection systems},
booktitle = {Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, DIMVA 2004},
year = {2004},
editor = {Flegel, Ulrich AND Meier, Michael} ,
pages = { 9-24 },
publisher = {Gesellschaft für Informatik e.V.},
address = {Bonn}
}
DateienGroesseFormatAnzeige
GI.Proceedings.46-1.pdf320.0Kb PDF Öffnen

Haben Sie fehlerhafte Angaben entdeckt? Sagen Sie uns Bescheid: Feedback abschicken

Mehr Information

ISBN: 3-88579-375-X
ISSN: 1617-5468
Datum: 2004
Sprache: en (en)
Typ: Text/Conference Paper
Sammlungen
  • P046 - DIMVA 2004 - Detection of intrusions and malware & vulnerability assessment, GI SIG SIDAR workshop, [15]

Zur Langanzeige


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.

 

 


Über uns | FAQ | Hilfe | Impressum | Datenschutz

Gesellschaft für Informatik e.V. (GI), Kontakt: Geschäftsstelle der GI
Diese Digital Library basiert auf DSpace.