메뉴 건너뛰기




Volumn 6201 LNCS, Issue , 2010, Pages 153-172

An online adaptive approach to alert correlation

Author keywords

alert correlation; Bayesian network

Indexed keywords

ADAPTIVE APPROACH; ALERT CORRELATION; ATTACK SCENARIOS; CAUSAL RELATIONSHIPS; DATA SETS; HONEYNET; INTRUSION ALERTS; INTRUSION DETECTION SYSTEMS; NETWORK ADMINISTRATOR; ON-THE-FLY; POTENTIAL STEPS; SYSTEM ADMINISTRATORS; TRAFFIC DATA; TWO STAGE;

EID: 77955041904     PISSN: 03029743     EISSN: 16113349     Source Type: Book Series    
DOI: 10.1007/978-3-642-14215-4_9     Document Type: Conference Paper
Times cited : (49)

References (26)
  • 1
    • 84947603083 scopus 로고    scopus 로고
    • Probabilistic alert correlation
    • Lee, W., Ḿe, L., Wespi, A. (eds.) RAID 2001. Springer, Heidelberg
    • Valdes, A., Skinner, K.: Probabilistic alert correlation. In: Lee, W., Ḿe, L., Wespi, A. (eds.) RAID 2001. LNCS, vol.2212, pp. 54-68. Springer, Heidelberg (2001)
    • (2001) LNCS , vol.2212 , pp. 54-68
    • Valdes, A.1    Skinner, K.2
  • 5
    • 84944201343 scopus 로고    scopus 로고
    • A language to model a database for detection of attacks
    • Debar, H., Ḿe, L., Wu, S.F. (eds.) RAID 2000. Springer, Heidelberg
    • Cuppens, F., Ortalo, R.: A language to model a database for detection of attacks. In: Debar, H., Ḿe, L., Wu, S.F. (eds.) RAID 2000. LNCS, vol.1907, pp. 197-216. Springer, Heidelberg (2000)
    • (2000) LNCS , vol.1907 , pp. 197-216
    • Cuppens, F.1    Ortalo, R.2
  • 7
    • 84862190056 scopus 로고    scopus 로고
    • A language driven IDS for event and alert correlation
    • Totel, E., Vivinis, B., Ḿe, L.: A language driven IDS for event and alert correlation. In: SEC, pp. 209-224 (2004)
    • (2004) SEC , pp. 209-224
    • Totel, E.1    Vivinis, B.2    Ḿe, L.3
  • 10
    • 63049125148 scopus 로고    scopus 로고
    • An incremental frequent structure mining framework for real-time alert correlation
    • Sadoddin, R., Ghorbani, A.A.: An incremental frequent structure mining framework for real-time alert correlation. Computers and Security 28, 153-173 (2009)
    • (2009) Computers and Security , vol.28 , pp. 153-173
    • Sadoddin, R.1    Ghorbani, A.A.2
  • 11
    • 53049102892 scopus 로고    scopus 로고
    • Building network attack graph for alert causal correlation
    • Zhang, S., Li, J., Chen, X., Fan, L.: Building network attack graph for alert causal correlation. Computers and Security 27, 188-196 (2008)
    • (2008) Computers and Security , vol.27 , pp. 188-196
    • Zhang, S.1    Li, J.2    Chen, X.3    Fan, L.4
  • 12
    • 66449085932 scopus 로고    scopus 로고
    • Reducing false positives in anomaly detectors through fuzzy alert aggregation
    • Maggia, F., Matteuccia, M., Zanero, S.: Reducing false positives in anomaly detectors through fuzzy alert aggregation. Information Fusion 10, 300-311 (2009)
    • (2009) Information Fusion , vol.10 , pp. 300-311
    • Maggia, F.1    Matteuccia, M.2    Zanero, S.3
  • 13
    • 3142623031 scopus 로고    scopus 로고
    • Clustering intrusion detection alarms to support root cause analysis
    • Julisch, K.: Clustering intrusion detection alarms to support root cause analysis. ACM Transactions on Information and System Security 6, 443-471 (2002)
    • (2002) ACM Transactions on Information and System Security , vol.6 , pp. 443-471
    • Julisch, K.1
  • 14
    • 26444436687 scopus 로고    scopus 로고
    • Using adaptive alert classification to reduce false positives in intrusion detection
    • Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. Springer, Heidelberg
    • Pietraszek, T.: Using adaptive alert classification to reduce false positives in intrusion detection. In: Jonsson, E., Valdes, A., Almgren, M. (eds.) RAID 2004. LNCS, vol.3224, pp. 102-124. Springer, Heidelberg (2004)
    • (2004) LNCS , vol.3224 , pp. 102-124
    • Pietraszek, T.1
  • 16
    • 67349164787 scopus 로고    scopus 로고
    • Processing intrusion detection alert aggregates with time series modeling
    • Viinikka, J., Debar, H., Ḿe, L.: Processing intrusion detection alert aggregates with time series modeling. Information Fusion 10, 312-324 (2009)
    • (2009) Information Fusion , vol.10 , pp. 312-324
    • Viinikka, J.1    Debar, H.2    Ḿe, L.3
  • 17
    • 77956988169 scopus 로고    scopus 로고
    • M2d2: A formal datamodel for IDS alert correlation
    • Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. Springer, Heidelberg
    • Morin, B., Ḿe, L., Debar,H.,Ducasse, M.:M2d2: A formal datamodel for IDS alert correlation. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.2516, pp. 115-137. Springer, Heidelberg (2002)
    • (2002) LNCS , vol.2516 , pp. 115-137
    • Morin, B.1    Ḿe, L.2    Debar, H.3    Ducasse, M.4
  • 18
    • 67349242974 scopus 로고    scopus 로고
    • A logic-based model to support alert correlation in intrusion detection
    • Morin, B., Ḿe, L., Debar, H., Ducasse, M.: A logic-based model to support alert correlation in intrusion detection. Information Fusion 10, 285-299 (2009)
    • (2009) Information Fusion , vol.10 , pp. 285-299
    • Morin, B.1    Ḿe, L.2    Debar, H.3    Ducasse, M.4
  • 24
    • 0003846041 scopus 로고
    • A tutorial on learning with bayesian networks
    • Microsoft Research
    • Heckerman, D.: A tutorial on learning with bayesian networks. Technical Report MSR-TR-95-106, Microsoft Research (1995)
    • (1995) Technical Report MSR-TR-95-106
    • Heckerman, D.1
  • 26
    • 77955018676 scopus 로고    scopus 로고
    • netForensics Honeynet team
    • netForensics Honeynet team: Honeynet traffic logs, http://old.honeynet. org/scans/scan34/
    • Honeynet Traffic Logs


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.