...
首页> 外文期刊>International journal of computer science and network security >A new Data Mining-based Approach to Improving the Quality of Alerts in Intrusion Detection Systems
【24h】

A new Data Mining-based Approach to Improving the Quality of Alerts in Intrusion Detection Systems

机译:一种新的基于数据挖掘的方法来提高入侵检测系统中警报的质量

获取原文
           

摘要

Data mining is about finding insights which are statistically reliable, unknown previously, and actionable from data. This data must be available, relevant, adequate, and clean. Also, the data mining problem must be well-defined, cannot be solved by query and reporting tools, and guided by a data mining process model Thus it is essential to use different security tools in order to protect computer systems and networks. Among these tools, Intrusion Detection Systems (IDSs) are one of the components of Defense-in-depth. One major drawback of IDSs is the generation of a huge number of alerts, most of which are false, redundant, or unimportant. Among different remedy approaches, many researchers proposed the use of data mining. Most of the research done in this area could not address the problems completely. Also, most of them suffer from human dependency and offline functionality. In this research, an online approach is proposed in order to manage alerts issued by IDSs. The proposed approach is able to process alerts produced by heterogeneous IDS systems. The approach is evaluated using DARPA 1999 dataset and Shahid Rajaee Port Complex dataset. Evaluation results show that the proposed approach can reduce the number of alerts by 94.32%, effectively improving alert management process. Because of the utilization of ensemble methodology and ideal algorithms in the proposed methodology, it can advise network security specialist the talk about of the monitored network within an online manner.
机译:数据挖掘是关于寻找统计上可靠,以前未知且可从数据中采取行动的见解。这些数据必须是可用的,相关的,足够的和干净的。另外,数据挖掘问题必须定义明确,不能由查询和报告工具解决,而必须由数据挖掘过程模型指导。因此,必须使用不同的安全工具来保护计算机系统和网络。在这些工具中,入侵检测系统(IDS)是纵深防御的组件之一。 IDS的一个主要缺点是生成大量警报,其中大多数警报是错误的,冗余的或不重要的。在不同的补救方法中,许多研究人员建议使用数据挖掘。在该领域进行的大多数研究无法完全解决问题。而且,它们中的大多数都受到人为依赖和脱机功能的困扰。在这项研究中,提出了一种在线方法来管理IDS发出的警报。所提出的方法能够处理由异构IDS系统产生的警报。使用DARPA 1999数据集和Shahid Rajaee Port Complex数据集对该方法进行了评估。评估结果表明,该方法可将警报数量减少94.32%,有效改善了警报管理流程。由于在建议的方法中采用了集成方法和理想算法,因此可以在线方式向网络安全专家建议有关受监视网络的信息。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号