메뉴 건너뛰기




Volumn 10, Issue 4, 2009, Pages 285-299

A logic-based model to support alert correlation in intrusion detection

Author keywords

Alert correlation; Data model; Intrusion detection

Indexed keywords

ALERT CORRELATION; DATA MODEL; DATA MODELS; INTRUSION DETECTION SYSTEMS; LARGE NETWORKS; LOGIC-BASED MODELS; SECURITY INCIDENT; SECURITY OPERATORS; SHARED DATA;

EID: 67349242974     PISSN: 15662535     EISSN: None     Source Type: Journal    
DOI: 10.1016/j.inffus.2009.01.005     Document Type: Article
Times cited : (74)

References (36)
  • 1
    • 77956988169 scopus 로고    scopus 로고
    • M2D2: a formal data model for IDS alert correlation
    • Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID'2002). Wespi A., Vigna G., and Deri L. (Eds), Springer
    • Morin B., Mé L., Debar H., and Ducassé M. M2D2: a formal data model for IDS alert correlation. In: Wespi A., Vigna G., and Deri L. (Eds). Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID'2002). Lecture Notes in Computer Science vol. 2516 (2002), Springer 115-127
    • (2002) Lecture Notes in Computer Science , vol.2516 , pp. 115-127
    • Morin, B.1    Mé, L.2    Debar, H.3    Ducassé, M.4
  • 4
    • 84947603083 scopus 로고    scopus 로고
    • Probabilistic alert correlation
    • W. Lee, L. Mé, A. Wespi (Eds, Proceedings of the Fourth International Symposium on the Recent Advances in Intrusion Detection RAID'2001
    • A. Valdes, K. Skinner, Probabilistic alert correlation, in: W. Lee, L. Mé, A. Wespi (Eds.), Proceedings of the Fourth International Symposium on the Recent Advances in Intrusion Detection (RAID'2001), LNCS, vol. 2212, 2001, pp. 54-68.
    • (2001) LNCS , vol.2212 , pp. 54-68
    • Valdes, A.1    Skinner, K.2
  • 7
    • 84947561772 scopus 로고    scopus 로고
    • Aggregation and correlation of intrusion-detection alerts
    • W. Lee, L. Mé, A. Wespi (Eds, Proceedings of the Fourth International Symposium on the Recent Advances in Intrusion Detection RAID'2001
    • H. Debar, A. Wespi, Aggregation and correlation of intrusion-detection alerts, in: W. Lee, L. Mé, A. Wespi (Eds.), Proceedings of the Fourth International Symposium on the Recent Advances in Intrusion Detection (RAID'2001), LNCS, vol. 2212, 2001, pp. 85-103.
    • (2001) LNCS , vol.2212 , pp. 85-103
    • Debar, H.1    Wespi, A.2
  • 9
    • 33745126677 scopus 로고    scopus 로고
    • B. Morin, H. Debar, Conceptual analysis of intrusion alarms, in: F. Roli, S. Vitulano (Eds.), 13th International Conference on Image Analysis and Processing, Lecture Notes in Computer Science, 3617, 2005, pp. 91-98 (special session on Computer Security).
    • B. Morin, H. Debar, Conceptual analysis of intrusion alarms, in: F. Roli, S. Vitulano (Eds.), 13th International Conference on Image Analysis and Processing, Lecture Notes in Computer Science, vol. 3617, 2005, pp. 91-98 (special session on Computer Security).
  • 10
    • 33646160004 scopus 로고    scopus 로고
    • Correlation of intrusion symptoms: an application of chronicles
    • Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection (RAID'2003). Vigna G., Jonsson E., and Krügel C. (Eds), Springer
    • Morin B., and Debar H. Correlation of intrusion symptoms: an application of chronicles. In: Vigna G., Jonsson E., and Krügel C. (Eds). Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection (RAID'2003). Lecture Notes in Computer Science vol. 2820 (2003), Springer 94-112
    • (2003) Lecture Notes in Computer Science , vol.2820 , pp. 94-112
    • Morin, B.1    Debar, H.2
  • 13
    • 84944201343 scopus 로고    scopus 로고
    • LAMBDA: A language to model a database for detection of attacks
    • H. Debar, L. Mé, S.F. Wu (Eds, Proceedings of the Third International Workshop on the Recent Advances in Intrusion Detection RAID'2000
    • F. Cuppens, R. Ortalo, LAMBDA: a language to model a database for detection of attacks, in: H. Debar, L. Mé, S.F. Wu (Eds.), Proceedings of the Third International Workshop on the Recent Advances in Intrusion Detection (RAID'2000), LNCS, vol. 1907, 2000, pp. 197-216.
    • (2000) LNCS , vol.1907 , pp. 197-216
    • Cuppens, F.1    Ortalo, R.2
  • 20
    • 67349256675 scopus 로고    scopus 로고
    • Camelis: a logical information system to organize and browse a collection of documents
    • Ferre S. Camelis: a logical information system to organize and browse a collection of documents. International Journal of General Systems 38 4 (2009)
    • (2009) International Journal of General Systems , vol.38 , Issue.4
    • Ferre, S.1
  • 22
    • 67349092010 scopus 로고    scopus 로고
    • H. Debar, D. Curry, RFC 4765, IETF, November 2006.
    • H. Debar, D. Curry, RFC 4765, IETF, November 2006.
  • 26
    • 26944484588 scopus 로고    scopus 로고
    • Modeling computer attacks: An ontology for intrusion detection
    • G. Vigna, E. Jonsson, C. Krügel (Eds, Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection RAID'2003, Springer
    • J. Undercoffer, A. Joshi, J. Pinkston, Modeling computer attacks: An ontology for intrusion detection, in: G. Vigna, E. Jonsson, C. Krügel (Eds.), Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection (RAID'2003), Lecture Notes in Computer Science, vol. 2820, Springer, 2003, pp. 113-135.
    • (2003) Lecture Notes in Computer Science , vol.2820 , pp. 113-135
    • Undercoffer, J.1    Joshi, A.2    Pinkston, J.3
  • 28
    • 0002067431 scopus 로고    scopus 로고
    • NetSTAT: a network-based intrusion detection system
    • Vigna G., and Kemmerer R.A. NetSTAT: a network-based intrusion detection system. Journal of Computer Security 7 1 (1999) 37-71
    • (1999) Journal of Computer Security , vol.7 , Issue.1 , pp. 37-71
    • Vigna, G.1    Kemmerer, R.A.2
  • 29
    • 84958955499 scopus 로고    scopus 로고
    • A mission-impact-based approach to infosec alarm correlation
    • A. Wespi, G. Vigna, L. Deri (Eds, Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection RAID'2002, Springer
    • P.A. Porras, M.W. Fong, A. Valdes, A mission-impact-based approach to infosec alarm correlation, in: A. Wespi, G. Vigna, L. Deri (Eds.), Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID'2002), Lecture Notes in Computer Science, vol. 2516, Springer, 2002, pp. 95-114.
    • (2002) Lecture Notes in Computer Science , vol.2516 , pp. 95-114
    • Porras, P.A.1    Fong, M.W.2    Valdes, A.3
  • 32
    • 0034316644 scopus 로고    scopus 로고
    • Modeling requests among cooperating intrusion detection systems
    • P. Ning, X.S. Wang, S. Jajodia, Modeling requests among cooperating intrusion detection systems, in: Computer Communications, vol. 23, 2000, pp. 1702-1716.
    • (2000) Computer Communications , vol.23 , pp. 1702-1716
    • Ning, P.1    Wang, X.S.2    Jajodia, S.3
  • 36
    • 33750945328 scopus 로고    scopus 로고
    • Using description logics for network vulnerability analysis
    • Mobile Communications and Learning Technologies, IEEE Computer Society
    • R. Zakeri, R. Jalili, H.R. Shahriari, H. Abolhassani, Using description logics for network vulnerability analysis, in: International Conference on Networking, Systems, Mobile Communications and Learning Technologies, IEEE Computer Society, 2006.
    • (2006) International Conference on Networking, Systems
    • Zakeri, R.1    Jalili, R.2    Shahriari, H.R.3    Abolhassani, H.4


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.