کد مقاله کد نشریه سال انتشار مقاله انگلیسی نسخه تمام متن
528439 869570 2009 17 صفحه PDF دانلود رایگان
عنوان انگلیسی مقاله ISI
Integrating intrusion alert information to aid forensic explanation: An analytical intrusion detection framework for distributive IDS
موضوعات مرتبط
مهندسی و علوم پایه مهندسی کامپیوتر چشم انداز کامپیوتر و تشخیص الگو
پیش نمایش صفحه اول مقاله
Integrating intrusion alert information to aid forensic explanation: An analytical intrusion detection framework for distributive IDS
چکیده انگلیسی

The objective of this research is to show an analytical intrusion detection framework (AIDF) comprised of (i) a probability model discovery approach, and (ii) a probabilistic inference mechanism for generating the most probable forensic explanation based on not only just the observed intrusion detection alerts, but also the unreported signature rules that are revealed in the probability model. The significance of the proposed probabilistic inference is its ability to integrate alert information available from IDS sensors distributed across subnets. We choose the open source Snort to illustrate its feasibility, and demonstrate the inference process applied to the intrusion detection alerts produced by Snort. Through a preliminary experimental study, we illustrate the applicability of AIDF for information integration and the realization of (i) a distributive IDS environment comprised of multiple sensors, and (ii) a mechanism for selecting and integrating the probabilistic inference results from multiple models for composing the most probable forensic explanation.

ناشر
Database: Elsevier - ScienceDirect (ساینس دایرکت)
Journal: Information Fusion - Volume 10, Issue 4, October 2009, Pages 325–341
نویسندگان
,