Detail výsledku

An Analysis of Correlations of Intrusion Alerts in an NREN

BARTOŠ, V.; ŽÁDNÍK, M. An Analysis of Correlations of Intrusion Alerts in an NREN. In 2014 IEEE 19th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD). Athény: IEEE Communications Society, 2014. p. 305-309. ISBN: 978-1-4799-5725-5.
Typ
článek ve sborníku konference
Jazyk
anglicky
Autoři
Bartoš Václav, Ing., Ph.D., UPSY (FIT)
Žádník Martin, Ing., Ph.D., UPSY (FIT)
Abstrakt

An ever increasing impact and amount of network attacks have driven many organizations to deploy various network monitoring and analysis systems such as honeypots, intrusion detection systems, log analysers and flow monitors. Besides improving these systems a logical next step is to collect and correlate alerts from multiple systems distributed across organizations. The idea is to leverage a joint effect of multiple monitoring systems to build a more robust and efficient system, ideally, lacking the shortcomings of the individual contributing systems. This paper presents an analysis of alert reports gathered from several such detectors deployed in national research and education network (NREN). The analysis focuses on the correlations of reported events in temporal domain
as well as on the correlations of different event types.

Klíčová slova

network intrusion detection, malicious traffic, spatio-temporal correlations, alert aggregation

Rok
2014
Strany
305–309
Sborník
2014 IEEE 19th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD)
Konference
19th IEEE International Workshop on Computer-Aided Modeling Analysis and Design of Communication Links and Networks
ISBN
978-1-4799-5725-5
Vydavatel
IEEE Communications Society
Místo
Athény
DOI
UT WoS
000380484700062
EID Scopus
BibTeX
@inproceedings{BUT111532,
  author="Václav {Bartoš} and Martin {Žádník}",
  title="An Analysis of Correlations of Intrusion Alerts in an NREN",
  booktitle="2014 IEEE 19th International Workshop on Computer Aided Modeling and Design of Communication Links and Networks (CAMAD)",
  year="2014",
  pages="305--309",
  publisher="IEEE Communications Society",
  address="Athény",
  doi="10.1109/CAMAD.2014.7033255",
  isbn="978-1-4799-5725-5",
  url="https://www.fit.vut.cz/research/publication/10526/"
}
Soubory
Projekty
Centrum excelence IT4Innovations, MŠMT, Operační program Výzkum a vývoj pro inovace, ED1.1.00/02.0070, zahájení: 2011-01-01, ukončení: 2015-12-31, ukončen
Výzkumné skupiny
Pracoviště
Nahoru