Automatic generation of intrusion detection verification rules : report on research progress to September 1, 2008 / Frederic Massicotte, Yvan Labiche and Lionel C. Briand. : Co24-3/8-2008-2E-PDF

"An Intrusion Detection System (IDS) is a crucial element of a network security posture. One class of IDS, called signature-based network IDSs, monitors network traffic, looking for evidence of malicious behavior as specified in attack descriptions (referred to as signatures). Many studies have reported that IDSs can generate thousands of alarms a day, many of which are false alarms. The problem often lies in the low accuracy of IDS signatures. It is therefore important to have more accurate signatures in order to reduce the number of false alarms. One part of the false alarm problem is the inability of IDSs to verify attacks (i.e. distinguish between successful and failed attacks). If IDSs were able to accurately verify attacks, this would reduce the number of false alarms a network administrator has to investigate. In this note, we demonstrate the feasibility of using a data mining algorithm to automatically generate IDS verification rules. We show that this automated approach is effective in reducing the number of false alarms when compared to other widely used and maintained IDSs"--Abstract, page ii.

Lien permanent pour cette publication :
publications.gc.ca/pub?id=9.892654&sl=1

Renseignements sur la publication
Ministère/Organisme Communications Research Centre (Canada), issuing body.
Titre Automatic generation of intrusion detection verification rules : report on research progress to September 1, 2008 / Frederic Massicotte, Yvan Labiche and Lionel C. Briand.
Titre de la série CRC note ; VPNT2008/02
Type de publication Série - Voir l'enregistrement principal
Langue [Anglais]
Format Électronique
Document électronique
Note(s) "Ottawa, September 2008."
Digitized edition from print [produced by Innovation, Science and Economic Development Canada].
Includes bibliographical references (pages 13-14).
Issued also in print format.
Includes abstracts in English and French.
Information sur la publication Ottawa : Communication Research Centre Canada = Centre des recherches sur les communications Canada, 2008.
Auteur / Contributeur Massicotte, Frederic, author.
Description 1 online resource (iii, 14 pages) : illustrations.
Numéro de catalogue
  • Co24-3/8-2008-2E-PDF
Descripteurs Intrusion detection systems (Computer security)
Systèmes de détection d'intrusion (Sécurité informatique)
Demander des formats alternatifs
Pour demander une publication dans un format alternatif, remplissez le formulaire électronique des publications du gouvernement du Canada. Utilisez le champ du formulaire «question ou commentaire» pour spécifier la publication demandée.
Date de modification :