کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
447793 693487 2014 17 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
False alarm minimization techniques in signature-based intrusion detection systems: A survey
ترجمه فارسی عنوان
تکنیک های به حداقل رساندن هشدار جعلی در سیستم های تشخیص نفوذ مبتنی بر امضا: یک نظرسنجی
کلمات کلیدی
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
چکیده انگلیسی

A network based Intrusion Detection System (IDS) gathers and analyzes network packets and report possible low level security violations to a system administrator. In a large network setup, these low level and partial reports become unmanageable to the administrator resulting in some unattended events. Further it is known that state of the art IDS generate many false alarms. There are techniques proposed in IDS literature to minimize false alarms, many of which are widely used in practice in commercial Security Information and Event Management (SIEM) tools. In this paper, we review existing false alarm minimization techniques in signature-based Network Intrusion Detection System (NIDS). We give a taxonomy of false alarm minimization techniques in signature-based IDS and present the pros and cons of each class. We also study few of the prominent commercial SIEM tools which have implemented these techniques along with their performance. Finally, we conclude with some directions to the future research.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computer Communications - Volume 49, 1 August 2014, Pages 1–17
نویسندگان
, ,