메뉴 건너뛰기




Volumn , Issue , 2010, Pages 24-31

A flexible and efficient alert correlation platform for distributed IDS

Author keywords

IDS management; Memory based clustering; Memory based correlation; Memory based databases

Indexed keywords

ALERT CORRELATION; COLUMN-ORIENTED DATABASE; DATA STORAGE; DISTRIBUTED DEPLOYMENT; DISTRIBUTED IDS; END USERS; EXISTING PROBLEMS; FLEXIBLE INTEGRATION; IDS MANAGEMENT; INDEX TABLE; INTRUSION DETECTION SYSTEMS; LARGE-SCALE DEPLOYMENT; MALICIOUS BEHAVIOR; MANAGEMENT SYSTEMS; MEMORY-BASED CLUSTERING; MEMORY-BASED CORRELATION; MEMORY-BASED DATABASES; MULTIPLE PROCESSING; NETWORK COMMUNICATIONS; PLUG-INS; PROCESS NEEDS; PROCESSING ALGORITHMS; PROCESSING POWER; SHARE MEMORY; SIMPLE ALGORITHM; STANDARDIZED INTERFACES;

EID: 78650313678     PISSN: None     EISSN: None     Source Type: Conference Proceeding    
DOI: 10.1109/NSS.2010.26     Document Type: Conference Paper
Times cited : (26)

References (27)
  • 3
    • 0013347631 scopus 로고    scopus 로고
    • CVE Website, (Accessed March 2009)
    • Mitre Corporation: Common vulnerabilities and exposures, CVE Website: http://cve.mitre.org/, (Accessed March 2009).
    • Common Vulnerabilities and Exposures
  • 4
    • 3142623031 scopus 로고    scopus 로고
    • Clustering intrusion detection alarms to support root cause analysis
    • K. Julisch: Clustering intrusion detection alarms to support root cause analysis, In: ACM Transactions on Information and System Security, vol. 6, Issue 4, pp. 443-471 (2003).
    • (2003) ACM Transactions on Information and System Security , vol.6 , Issue.4 , pp. 443-471
    • Julisch, K.1
  • 6
    • 84947603083 scopus 로고    scopus 로고
    • Probabilistic alert correlation
    • Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID'00), London, UK, Springer
    • A. Valdes and K. Skinner: Probabilistic alert correlation, In: Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID'00), London, UK, Springer LNCS 2212, pp.54-68 (2001).
    • (2001) LNCS , vol.2212 , pp. 54-68
    • Valdes, A.1    Skinner, K.2
  • 7
    • 84947561772 scopus 로고    scopus 로고
    • Aggregation and correlation of intrusiondetection alerts
    • Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID'01), London, UK, Springer
    • H. Debar and A. Wespi: Aggregation and correlation of intrusiondetection alerts, In: Proceedings of the 4th International Symposium on Recent Advances in Intrusion Detection (RAID'01), London, UK, Springer LNCS 2212, pp. 85-103 (2001).
    • (2001) LNCS , vol.2212 , pp. 85-103
    • Debar, H.1    Wespi, A.2
  • 10
    • 33646844014 scopus 로고    scopus 로고
    • Statistical causality analysis of infosec alert data
    • Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection (RAID'03), London, UK, Springer
    • W. L. Xinzhou Qin: Statistical causality analysis of infosec alert data, In: Proceedings of the 6th International Symposium on Recent Advances in Intrusion Detection (RAID'03), London, UK, Springer LNCS 2820, pp. 73-93 (2003).
    • (2003) LNCS , vol.2820 , pp. 73-93
    • Xinzhou Qin, W.L.1
  • 14
    • 84958955499 scopus 로고    scopus 로고
    • A mission-impact-based approach to infosec alarm correlation
    • Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID'02), London, UK, Springer
    • P. A. Porras, M. W. Fong, and A. Valdes: A mission-impact-based approach to infosec alarm correlation, In: Proceedings of the 5th International Symposium on Recent Advances in Intrusion Detection (RAID'02), London, UK, Springer LNCS, pp. 95-114 (2002).
    • (2002) LNCS , pp. 95-114
    • Porras, P.A.1    Fong, M.W.2    Valdes, A.3
  • 18
    • 78650381677 scopus 로고    scopus 로고
    • WEBSITE, (accessed Nov 2009)
    • MonetDB: WEBSITE: http://monetdb.cwi.nl/ (accessed Nov 2009).
  • 20
    • 78650400609 scopus 로고    scopus 로고
    • WEBSITE, (accessed Nov 2009)
    • MySQL: WEBSITE: http://www.mysql.com/ (accessed Nov 2009).
  • 21
    • 78650410882 scopus 로고    scopus 로고
    • WEBSITE, (accessed Nov 2009)
    • PostgreSQL: WEBSITE: http://www.postgresql.org/ (accessed Nov 2009).
  • 22
    • 78650405265 scopus 로고    scopus 로고
    • WEBSITE, (accessed Nov 2009)
    • Snort IDS: WEBSITE: http://www.snort.org/ (accessed Nov 2009).
  • 25
    • 58449084939 scopus 로고    scopus 로고
    • Real-time alert correlation with type graphs
    • Proceedings of the 4th international Conference on Information Systems Security (ISS'09), Springer, Hyderabad, India
    • Tedesco, G. and Aickelin, U.: Real-Time Alert Correlation with Type Graphs, In: Proceedings of the 4th international Conference on Information Systems Security (ISS'09), Springer LNCS 5352, Hyderabad, India, pp. 173-187 (2008).
    • (2008) LNCS , vol.5352 , pp. 173-187
    • Tedesco, G.1    Aickelin, U.2


* 이 정보는 Elsevier사의 SCOPUS DB에서 KISTI가 분석하여 추출한 것입니다.