메뉴 건너뛰기




Volumn 3224, Issue , 2004, Pages 102-124

Using adaptive alert classification to reduce false positives in intrusion detection

Author keywords

Alert classification; False positives; Intrusion detection; Machine learning

Indexed keywords

ARTIFICIAL INTELLIGENCE; LEARNING SYSTEMS; MERCURY (METAL); NETWORK SECURITY;

EID: 26444436687     PISSN: 03029743     EISSN: 16113349     Source Type: Book Series    
DOI: 10.1007/978-3-540-30143-1_6     Document Type: Article
Times cited : (150)

References (36)
  • 1
    • 0004048154 scopus 로고
    • Computer security threat monitoring and surveillance
    • James P. Anderson Co
    • Anderson, J.P.: Computer security threat monitoring and surveillance. Technical report, James P. Anderson Co (1980).
    • (1980) Technical Report
    • Anderson, J.P.1
  • 4
    • 85149612939 scopus 로고
    • Fast effective rule induction
    • In Prieditis, A., Russell, S., eds.: Tahoe City, CA, Morgan Kaufmann
    • Cohen, W.W.: Fast effective rule induction. In Prieditis, A., Russell, S., eds.: Proceedings of the 12th International Conference on Machine Learning, Tahoe City, CA, Morgan Kaufmann (1995) 115-123.
    • (1995) Proceedings of the 12th International Conference on Machine Learning , pp. 115-123
    • Cohen, W.W.1
  • 7
    • 84947561772 scopus 로고    scopus 로고
    • Aggregation and correlation of intrusion-detection alerts
    • Recent Advances in Intrusion Detection (RAID2001). Springer-Verlag
    • Debar, H., Wespi, A.: Aggregation and correlation of intrusion-detection alerts. In: Recent Advances in Intrusion Detection (RAID2001). Volume 2212 of Lecture Notes in Computer Science., Springer-Verlag (2001) 85-103.
    • (2001) Lecture Notes in Computer Science. , vol.2212 , pp. 85-103
    • Debar, H.1    Wespi, A.2
  • 11
    • 0345438685 scopus 로고    scopus 로고
    • ROC graphs: Note and practical considerations for researchers (HPL-2003-4)
    • HP Laboratories
    • Fawcett, T.: ROC graphs: Note and practical considerations for researchers (HPL-2003-4). Technical report, HP Laboratories (2003).
    • (2003) Technical Report
    • Fawcett, T.1
  • 12
    • 0034499376 scopus 로고    scopus 로고
    • A Note on the Utility of Incremental Learning
    • Giraud-Carrier, C.: A Note on the Utility of Incremental Learning. AI Communications 13 (2000) 215-223.
    • (2000) AI Communications , vol.13 , pp. 215-223
    • Giraud-Carrier, C.1
  • 20
    • 84958970105 scopus 로고    scopus 로고
    • The effect of identifying vulnerabilities and patching software on the utility of network intrusion detection
    • Recent Advances in Intrusion Detection (RAID2002). Springer-Verlag
    • Lippmann, R., Webster, S., Stetson, D.: The effect of identifying vulnerabilities and patching software on the utility of network intrusion detection. In: Recent Advances in Intrusion Detection (RAID2002). Volume 2516 of Lecture Notes in Computer Science., Springer-Verlag (2002) 307-326.
    • (2002) Lecture Notes in Computer Science. , vol.2516 , pp. 307-326
    • Lippmann, R.1    Webster, S.2    Stetson, D.3
  • 21
    • 35248857893 scopus 로고    scopus 로고
    • An Analysis of the 1999 DARPA/Lincoln Laboratory Evaluation Data for Network Anomaly Detection
    • Recent Advances in Intrusion Detection (RAID2003). Springer-Verlag
    • Mahoney, M.V., Chan, P.K.: An Analysis of the 1999 DARPA/Lincoln Laboratory Evaluation Data for Network Anomaly Detection. In: Recent Advances in Intrusion Detection (RAID2003). Volume 2820 of Lecture Notes in Computer Science., Springer-Verlag (2003) 220-237.
    • (2003) Lecture Notes in Computer Science. , vol.2820 , pp. 220-237
    • Mahoney, M.V.1    Chan, P.K.2
  • 22
    • 84884637057 scopus 로고    scopus 로고
    • Incremental learning with partial instance memory
    • Proceedings of Foundations of Intelligent Systems: 13th International Symposium, ISMIS 2002. Springer-Verlag
    • Maloof, M.A., Michalski, R.S.: Incremental learning with partial instance memory. In: Proceedings of Foundations of Intelligent Systems: 13th International Symposium, ISMIS 2002. Volume 2366 of Lecture Notes in Artificial Intelligence., Springer-Verlag (2002) 16-27.
    • (2002) Lecture Notes in Artificial Intelligence. , vol.2366 , pp. 16-27
    • Maloof, M.A.1    Michalski, R.S.2
  • 25
    • 84944239811 scopus 로고    scopus 로고
    • The 1998 Lincoln Laboratory IDS Evaluation. A critique
    • Recent Advances in Intrusion Detection (RAID2000). Springer-Verlag
    • McHugh, J.: The 1998 Lincoln Laboratory IDS Evaluation. A critique. In: Recent Advances in Intrusion Detection (RAID2000). Volume 1907 of Lecture Notes in Computer Science., Springer-Verlag (2000) 145-161.
    • (2000) Lecture Notes in Computer Science. , vol.1907 , pp. 145-161
    • McHugh, J.1
  • 28
    • 77956988169 scopus 로고    scopus 로고
    • M2D2: A formal data model for IDS alert correlation
    • Recent Advances in Intrusion Detection (RAID2002). Springer-Verlag
    • Morin, B., Mé, L., Debar, H., Ducasse, M.: M2D2: A formal data model for IDS alert correlation. In: Recent Advances in Intrusion Detection (RAID2002). Volume 2516 of Lecture Notes in Computer Science., Springer-Verlag (2002) 115-137.
    • (2002) Lecture Notes in Computer Science. , vol.2516 , pp. 115-137
    • Morin, B.1    Mé, L.2    Debar, H.3    Ducasse, M.4
  • 29
    • 0035283313 scopus 로고    scopus 로고
    • Robust classification for impresice environments
    • Provost, F., Fawcett, T.: Robust classification for impresice environments. Machine Learning Journal 42 (2001) 203-231.
    • (2001) Machine Learning Journal , vol.42 , pp. 203-231
    • Provost, F.1    Fawcett, T.2
  • 33
    • 84947759699 scopus 로고    scopus 로고
    • Inducing cost-sensitive trees via instance weighting
    • Proceedings of The Second European Symposium on Principles of Data Mining and Knowledge Discovery. Springer-Verlag
    • Ting, K.: Inducing cost-sensitive trees via instance weighting. In: Proceedings of The Second European Symposium on Principles of Data Mining and Knowledge Discovery. Volume 1510 of Lecture Notes in AI., Springer-Verlag (1998) 139-147.
    • (1998) Lecture Notes in AI. , vol.1510 , pp. 139-147
    • Ting, K.1
  • 34
    • 84947603083 scopus 로고    scopus 로고
    • Probabilistic alert correlation
    • Recent Advances in Intrusion Detection (RAID2001). Springer-Verlag
    • Valdes, A., Skinner, K.: Probabilistic alert correlation. In: Recent Advances in Intrusion Detection (RAID2001). Volume 2212 of Lecture Notes in Computer Science., Springer-Verlag (2001) 54-68.
    • (2001) Lecture Notes in Computer Science. , vol.2212 , pp. 54-68
    • Valdes, A.1    Skinner, K.2
  • 35
    • 84947286061 scopus 로고    scopus 로고
    • Measuring false-positive by automated real-time correlated hacking behavior analysis
    • Volume 2200 of Lecture Notes in Computer Science., Springer-Verlag
    • Wang, J., Lee, I.: Measuring false-positive by automated real-time correlated hacking behavior analysis. In: Information Security 4th International Conference. Volume 2200 of Lecture Notes in Computer Science., Springer-Verlag (2001) 512.
    • (2001) Information Security 4th International Conference , pp. 512
    • Wang, J.1    Lee, I.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.