کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
456152 695655 2010 10 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Reducing false positives in intrusion detection systems
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Reducing false positives in intrusion detection systems
چکیده انگلیسی

A post-processing filter is proposed to reduce false positives in network-based intrusion detection systems. The filter comprises three components, each one of which is based upon statistical properties of the input alert set. Special characteristics of alerts corresponding to true attacks are exploited. These alerts may be observed in batches, which contain similarities in the source or destination IPs, or they may produce abnormalities in the distribution of alerts of the same signature. False alerts can be recognized by the frequency with which their signature triggers false positives. The filter architecture and design are discussed. Evaluation results performed using the DARPA 1999 dataset indicate that the proposed approach can significantly reduce the number and percentage of false positives produced by Snort© (Roesch, 1999). Our filter limited false positives by a percentage up to 75%.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Computers & Security - Volume 29, Issue 1, February 2010, Pages 35–44
نویسندگان
, ,