2010 | OriginalPaper | Buchkapitel
A Simple Method for Improving Intrusion Detections in Corporate Networks
verfasst von : Joshua Ojo Nehinbe
Erschienen in: Information Security and Digital Forensics
Verlag: Springer Berlin Heidelberg
Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.
Wählen Sie Textabschnitte aus um mit Künstlicher Intelligenz passenden Patente zu finden. powered by
Markieren Sie Textabschnitte, um KI-gestützt weitere passende Inhalte zu finden. powered by
Intrusion redundancies are fundamental flaws of all intrusion detection systems. Over the years, these are frequently exploited by stealthy attackers to conceal network attacks because it is fundamentally difficult to discern false alerts from true positives in a massive dataset. Consequently, attacks that are concealed in massive datasets often go undetected. Accordingly, the jobs of system administrators and the return on investment on network intrusion detectors are often threatened. Therefore, this paper presents clustering method that we have designed to lessen these problems. We have broadly evaluated our method on six datasets that comprised of synthetic and realistic attacks. Alerts of each dataset were clustered into equivalent and unique alerts and a cluster of unique alerts was eventually synthesized from them. The results that we have obtained have indicated how system administrators could achieve substantial reduction of redundancies in corporate networks.