Real-time analysis of intrusion detection alerts via correlation연관성 분석 기술을 이용한 실시간 침입탐지정보 분석시스템에 관한 연구

Cited 0 time in webofscience Cited 0 time in scopus
  • Hit : 449
  • Download : 0
DC FieldValueLanguage
dc.contributor.advisorYoon, Hyun-Soo-
dc.contributor.advisor윤현수-
dc.contributor.authorLee, Soo-Jin-
dc.contributor.author이수진-
dc.date.accessioned2011-12-13T05:21:32Z-
dc.date.available2011-12-13T05:21:32Z-
dc.date.issued2006-
dc.identifier.urihttp://library.kaist.ac.kr/search/detail/view.do?bibCtrlNo=254440&flag=dissertation-
dc.identifier.urihttp://hdl.handle.net/10203/32912-
dc.description학위논문(박사) - 한국과학기술원 : 전산학전공, 2006.2, [ ix, 67 p. ]-
dc.description.abstractWith the growing deployment of networks and the Internet, the importance of network security has increased. Recently, however, systems that detect intrusions, which are important in security countermeasures, have been unable to provide proper analysis or an effective defense mechanism. Instead, they have overwhelmed human operators with a large volume of intrusion detection alerts. In addition, their content is so poor that it requires the human operator to go back to the original data source to acquire the necessary information. That is, human operators are fully responsible for analyzing a network``s status and the trends of cyber attacks. Moreover, although cyber attacks can produce multiple correlated alerts, IDSs are generally unable to detect such attacks as a complex single attack but regard each alert as a separate attack. Therefore, in the early-stage, it is difficult to detect large-scale attacks such as a distributed denial of service(DDoS) or a worm. To address this problem, many researchers have proposed a technique named alert correlation. Unfortunately, even though a number of correlation approaches have been suggested, most approaches have several limitations: shortage of practicality, additional overhead of human operators that cannot be ignored, neglect of the importance of time information, and so on. We therefore propose a fast and efficient system for analyzing alerts via correlation. In proposing the system, we focused on providing flexibility, automation, and real-time processing capability. Our system basically depends on the probabilistic correlation. However, we enhance the probabilistic correlation by applying more systematically defined similarity functions and also present a new correlation component that is absent in other correlation models. Compared with other models, our model has several advantages. First, we considered the time similarity, though this major measure of correlation is disregarded in other models, and we ...eng
dc.languageeng-
dc.publisher한국과학기술원-
dc.subjectAlert analysis-
dc.subjectIntrusion detection system-
dc.subjectCorrelation-
dc.subject연관성 분석-
dc.subject침입탐지정보 분석-
dc.subject침입탐지 시스템-
dc.titleReal-time analysis of intrusion detection alerts via correlation-
dc.title.alternative연관성 분석 기술을 이용한 실시간 침입탐지정보 분석시스템에 관한 연구-
dc.typeThesis(Ph.D)-
dc.identifier.CNRN254440/325007 -
dc.description.department한국과학기술원 : 전산학전공, -
dc.identifier.uid020025223-
dc.contributor.localauthorYoon, Hyun-Soo-
dc.contributor.localauthor윤현수-
Appears in Collection
CS-Theses_Ph.D.(박사논문)
Files in This Item
There are no files associated with this item.

qr_code

  • mendeley

    citeulike


rss_1.0 rss_2.0 atom_1.0