메뉴 건너뛰기




Volumn 36, Issue 8, 2009, Pages 11145-11155

A decision support system for constructing an alert classification model

Author keywords

Alert classification; Decision support system; Intrusion detection; Model construction; Sequential pattern mining

Indexed keywords

ALERT CLASSIFICATION; ALERT PROCESSING; ANALYSIS METHOD; ATTACK PATTERNS; ATTACK SEQUENCES; CLASSIFICATION RULES; DATA FORMAT; INTRUSION PATTERNS; MODEL CONSTRUCTION; NETWORK ADMINISTRATOR; NETWORK DATA; NETWORK INTRUSIONS; ON-LINE NETWORK; PREPROCESSING PHASE; RAPID GROWTH; ROOT CAUSE; ROOTKITS; SEQUENTIAL PATTERN MINING; THREE PHASIS; TIME INTERVAL;

EID: 67349095739     PISSN: 09574174     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.eswa.2009.02.097     Document Type: Article
Times cited : (29)

References (27)
  • 2
    • 26444495635 scopus 로고    scopus 로고
    • IDS false alarm reduction using continuous and discontinuous patterns
    • Alharby, A., & Imai, H. (2005). IDS false alarm reduction using continuous and discontinuous patterns. In Proceedings of ACNS 2005 (pp. 192-205).
    • (2005) Proceedings of ACNS , pp. 192-205
    • Alharby, A.1    Imai, H.2
  • 4
    • 2342536664 scopus 로고    scopus 로고
    • Powerful attack cripples majority of key Internet computers
    • Bridis, T. (2002). Powerful attack cripples majority of key Internet computers. In Yahoo! news.
    • (2002) Yahoo! news
    • Bridis, T.1
  • 6
    • 67349201180 scopus 로고    scopus 로고
    • URL
    • CERT Coordination Center (2006). URL: .
    • (2006)
  • 7
    • 0040377588 scopus 로고    scopus 로고
    • NiagaraCQ: A scalable continuous query system for internet databases
    • Chen, J., DeWitt, D. J., Tian, F., & Wang, Y. (2000). NiagaraCQ: A scalable continuous query system for internet databases. In Proceedings of ACM SIGMOD 2000 (pp. 379-390).
    • (2000) Proceedings of ACM SIGMOD , pp. 379-390
    • Chen, J.1    DeWitt, D.J.2    Tian, F.3    Wang, Y.4
  • 9
    • 67349216897 scopus 로고    scopus 로고
    • DRAMA Expert System, URL
    • DRAMA Expert System, CORETECH Inc. (2006). URL: .
    • (2006) CORETECH Inc
  • 12
    • 67349119012 scopus 로고    scopus 로고
    • Master thesis, National Chiao Tung University, Hsinchu, Taiwan, ROC
    • Hsin, W. Y. (2005). A study of alert-based collaborative defense. Master thesis, National Chiao Tung University, Hsinchu, Taiwan, ROC.
    • (2005) A study of alert-based collaborative defense
    • Hsin, W.Y.1
  • 15
    • 3242772995 scopus 로고    scopus 로고
    • Constructing detection knowledge for DDoS intrusion tolerance
    • Lin S.C., and Tseng S.S. Constructing detection knowledge for DDoS intrusion tolerance. Expert Systems with Applications 27 (2004) 379-390
    • (2004) Expert Systems with Applications , vol.27 , pp. 379-390
    • Lin, S.C.1    Tseng, S.S.2
  • 23
    • 26444529309 scopus 로고    scopus 로고
    • False alarm classification model for network-based intrusion detection system
    • Shin, M. S., Kim, E. H., & Ryu, K. H. (2004). False alarm classification model for network-based intrusion detection system. In Proceedings of IDEAL 2004 (pp. 259-265).
    • (2004) Proceedings of IDEAL , pp. 259-265
    • Shin, M.S.1    Kim, E.H.2    Ryu, K.H.3
  • 25
    • 67349217973 scopus 로고    scopus 로고
    • Symantec Corp. (2006). Symantec internet security threat report: Trends for July 05-Decamber 05. In IX. URL: .
    • Symantec Corp. (2006). Symantec internet security threat report: Trends for July 05-Decamber 05. In Vol. IX. URL: .
  • 27
    • 0037328484 scopus 로고    scopus 로고
    • Sustaining availability of web services under distributed denial of service attacks
    • Xu, J., & Lee, W. (2003). Sustaining availability of web services under distributed denial of service attacks. In IEEE transactions on computers (Vol. 52(2)) (pp. 195-208).
    • (2003) IEEE transactions on computers , vol.52 , Issue.2 , pp. 195-208
    • Xu, J.1    Lee, W.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.