Real-time analysis of intrusion detection alerts via correlation연관성 분석 기술을 이용한 실시간 침입탐지정보 분석시스템에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 446
  • Download : 0
With the growing deployment of networks and the Internet, the importance of network security has increased. Recently, however, systems that detect intrusions, which are important in security countermeasures, have been unable to provide proper analysis or an effective defense mechanism. Instead, they have overwhelmed human operators with a large volume of intrusion detection alerts. In addition, their content is so poor that it requires the human operator to go back to the original data source to acquire the necessary information. That is, human operators are fully responsible for analyzing a network``s status and the trends of cyber attacks. Moreover, although cyber attacks can produce multiple correlated alerts, IDSs are generally unable to detect such attacks as a complex single attack but regard each alert as a separate attack. Therefore, in the early-stage, it is difficult to detect large-scale attacks such as a distributed denial of service(DDoS) or a worm. To address this problem, many researchers have proposed a technique named alert correlation. Unfortunately, even though a number of correlation approaches have been suggested, most approaches have several limitations: shortage of practicality, additional overhead of human operators that cannot be ignored, neglect of the importance of time information, and so on. We therefore propose a fast and efficient system for analyzing alerts via correlation. In proposing the system, we focused on providing flexibility, automation, and real-time processing capability. Our system basically depends on the probabilistic correlation. However, we enhance the probabilistic correlation by applying more systematically defined similarity functions and also present a new correlation component that is absent in other correlation models. Compared with other models, our model has several advantages. First, we considered the time similarity, though this major measure of correlation is disregarded in other models, and we ...
Advisors
Yoon, Hyun-Sooresearcher윤현수researcher
Description
한국과학기술원 : 전산학전공,
Publisher
한국과학기술원
Issue Date
2006
Identifier
254440/325007  / 020025223
Language
eng
Description

학위논문(박사) - 한국과학기술원 : 전산학전공, 2006.2, [ ix, 67 p. ]

Keywords

Alert analysis; Intrusion detection system; Correlation; 연관성 분석; 침입탐지정보 분석; 침입탐지 시스템

URI
http://hdl.handle.net/10203/32912
Link
http://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=254440&flag=dissertation
Appears in Collection
CS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0