کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
494368 862715 2007 17 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Building intrusion pattern miner for Snort network intrusion detection system
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر شبکه های کامپیوتری و ارتباطات
پیش نمایش صفحه اول مقاله
Building intrusion pattern miner for Snort network intrusion detection system
چکیده انگلیسی

In this paper, we enhance the functionalities of Snort network-based intrusion detection system to automatically generate patterns of misuse from attack data, and the ability of detecting sequential intrusion behaviors. To that, we implement an intrusion pattern discovery module which applies data mining technique to extract single intrusion patterns and sequential intrusion patterns from a collection of attack packets, and then converts the patterns to Snort detection rules for on-line intrusion detection. In order to detect sequential intrusion behavior, the Snort detection engine is accompanied with our intrusion behavior detection engine. Intrusion behavior detection engine will create an alert when a series of incoming packets match the signatures representing sequential intrusion scenarios.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Journal of Systems and Software - Volume 80, Issue 10, October 2007, Pages 1699–1715
نویسندگان
, , ,