-
1
-
-
84947603083
-
Probabilistic alert correlation
-
Lee, W., Ḿe, L., Wespi, A. (eds.) RAID 2001. Springer, Heidelberg
-
Valdes, A., Skinner, K.: Probabilistic alert correlation. In: Lee, W., Ḿe, L., Wespi, A. (eds.) RAID 2001. LNCS, vol.2212, pp. 54-68. Springer, Heidelberg (2001)
-
(2001)
LNCS
, vol.2212
, pp. 54-68
-
-
Valdes, A.1
Skinner, K.2
-
2
-
-
0038011185
-
Constructing attacks scenarios through correlation of intrusion alerts
-
Ning, P., Cui, Y., Reeves, D.S.: Constructing attacks scenarios through correlation of intrusion alerts. In: Proceedings of the 9th ACM conference on Computer and communications security, pp. 245-254 (2002)
-
(2002)
Proceedings of the 9th ACM Conference on Computer and Communications Security
, pp. 245-254
-
-
Ning, P.1
Cui, Y.2
Reeves, D.S.3
-
3
-
-
84860495162
-
Modeling multistep cyber attacks for scenario recognition
-
Cheung, S., Lindqvist, U., Fong, M.: Modeling multistep cyber attacks for scenario recognition. In: DARPA Information Survivability Conference and Exposition, vol.1, pp. 284-292 (2003)
-
(2003)
DARPA Information Survivability Conference and Exposition
, vol.1
, pp. 284-292
-
-
Cheung, S.1
Lindqvist, U.2
Fong, M.3
-
5
-
-
84944201343
-
A language to model a database for detection of attacks
-
Debar, H., Ḿe, L., Wu, S.F. (eds.) RAID 2000. Springer, Heidelberg
-
Cuppens, F., Ortalo, R.: A language to model a database for detection of attacks. In: Debar, H., Ḿe, L., Wu, S.F. (eds.) RAID 2000. LNCS, vol.1907, pp. 197-216. Springer, Heidelberg (2000)
-
(2000)
LNCS
, vol.1907
, pp. 197-216
-
-
Cuppens, F.1
Ortalo, R.2
-
6
-
-
0036090387
-
Statl: An attack language for statebased intrusion detection
-
Eckmann, S.T., Vigna, G., Kemmerer, R.A.: Statl: An attack language for statebased intrusion detection. Journal of Computer Security 10, 71-103 (2002)
-
(2002)
Journal of Computer Security
, vol.10
, pp. 71-103
-
-
Eckmann, S.T.1
Vigna, G.2
Kemmerer, R.A.3
-
7
-
-
84862190056
-
A language driven IDS for event and alert correlation
-
Totel, E., Vivinis, B., Ḿe, L.: A language driven IDS for event and alert correlation. In: SEC, pp. 209-224 (2004)
-
(2004)
SEC
, pp. 209-224
-
-
Totel, E.1
Vivinis, B.2
Ḿe, L.3
-
10
-
-
63049125148
-
An incremental frequent structure mining framework for real-time alert correlation
-
Sadoddin, R., Ghorbani, A.A.: An incremental frequent structure mining framework for real-time alert correlation. Computers and Security 28, 153-173 (2009)
-
(2009)
Computers and Security
, vol.28
, pp. 153-173
-
-
Sadoddin, R.1
Ghorbani, A.A.2
-
11
-
-
53049102892
-
Building network attack graph for alert causal correlation
-
Zhang, S., Li, J., Chen, X., Fan, L.: Building network attack graph for alert causal correlation. Computers and Security 27, 188-196 (2008)
-
(2008)
Computers and Security
, vol.27
, pp. 188-196
-
-
Zhang, S.1
Li, J.2
Chen, X.3
Fan, L.4
-
12
-
-
66449085932
-
Reducing false positives in anomaly detectors through fuzzy alert aggregation
-
Maggia, F., Matteuccia, M., Zanero, S.: Reducing false positives in anomaly detectors through fuzzy alert aggregation. Information Fusion 10, 300-311 (2009)
-
(2009)
Information Fusion
, vol.10
, pp. 300-311
-
-
Maggia, F.1
Matteuccia, M.2
Zanero, S.3
-
13
-
-
3142623031
-
Clustering intrusion detection alarms to support root cause analysis
-
Julisch, K.: Clustering intrusion detection alarms to support root cause analysis. ACM Transactions on Information and System Security 6, 443-471 (2002)
-
(2002)
ACM Transactions on Information and System Security
, vol.6
, pp. 443-471
-
-
Julisch, K.1
-
14
-
-
26444436687
-
Using adaptive alert classification to reduce false positives in intrusion detection
-
Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. Springer, Heidelberg
-
Pietraszek, T.: Using adaptive alert classification to reduce false positives in intrusion detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.3224, pp. 102-124. Springer, Heidelberg (2004)
-
(2004)
LNCS
, vol.3224
, pp. 102-124
-
-
Pietraszek, T.1
-
15
-
-
0034301662
-
A data mining analysis of rtid alarms
-
Manganaris, S., Christensen, M., Zerkle, D., Hermiz, K.: A data mining analysis of rtid alarms. Computer Networks: The International Journal of Computer and Telecommunications Networking 34, 571-577 (2000)
-
(2000)
Computer Networks: The International Journal of Computer and Telecommunications Networking
, vol.34
, pp. 571-577
-
-
Manganaris, S.1
Christensen, M.2
Zerkle, D.3
Hermiz, K.4
-
16
-
-
67349164787
-
Processing intrusion detection alert aggregates with time series modeling
-
Viinikka, J., Debar, H., Ḿe, L.: Processing intrusion detection alert aggregates with time series modeling. Information Fusion 10, 312-324 (2009)
-
(2009)
Information Fusion
, vol.10
, pp. 312-324
-
-
Viinikka, J.1
Debar, H.2
Ḿe, L.3
-
17
-
-
77956988169
-
M2d2: A formal datamodel for IDS alert correlation
-
Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. Springer, Heidelberg
-
Morin, B., Ḿe, L., Debar,H.,Ducasse, M.:M2d2: A formal datamodel for IDS alert correlation. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.2516, pp. 115-137. Springer, Heidelberg (2002)
-
(2002)
LNCS
, vol.2516
, pp. 115-137
-
-
Morin, B.1
Ḿe, L.2
Debar, H.3
Ducasse, M.4
-
18
-
-
67349242974
-
A logic-based model to support alert correlation in intrusion detection
-
Morin, B., Ḿe, L., Debar, H., Ducasse, M.: A logic-based model to support alert correlation in intrusion detection. Information Fusion 10, 285-299 (2009)
-
(2009)
Information Fusion
, vol.10
, pp. 285-299
-
-
Morin, B.1
Ḿe, L.2
Debar, H.3
Ducasse, M.4
-
19
-
-
84958955499
-
A mission-impact-based approach to infosec alarm correlation
-
Porras, P.A., Fong, M.W., Valdes, A.: A mission-impact-based approach to infosec alarm correlation. In: Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection, pp. 95-114 (2002)
-
(2002)
Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection
, pp. 95-114
-
-
Porras, P.A.1
Fong, M.W.2
Valdes, A.3
-
24
-
-
0003846041
-
A tutorial on learning with bayesian networks
-
Microsoft Research
-
Heckerman, D.: A tutorial on learning with bayesian networks. Technical Report MSR-TR-95-106, Microsoft Research (1995)
-
(1995)
Technical Report MSR-TR-95-106
-
-
Heckerman, D.1
-
26
-
-
77955018676
-
-
netForensics Honeynet team
-
netForensics Honeynet team: Honeynet traffic logs, http://old.honeynet. org/scans/scan34/
-
Honeynet Traffic Logs
-
-
|