【24h】

Design and Implementation of A Distributed IDS Alert Aggregation Model

机译:分布式IDS警报聚集模型的设计与实现

获取原文
获取原文并翻译 | 示例

摘要

How to aggregate and reduce duplicated alerts from different IDSs is one of the most important problems in distributed IDS research area. The article proposes a distributed alert aggregation model composed of local components and network components. Local components transform raw alerts originating from traditional IDSs to IDMEF-based alerts with uniform format, which are sent to network components. Network components aggregate similar alerts into a meta-alert, using an aggregation algorithm based on category and feature similarity. A subscription-based communication mechanism is and multiple kinds of messages are also proposed to meet the demands of the communication between the components and to realize information share in the whole network. Experiments on DARPA99 data set indicated the effectiveness of the model.
机译:如何汇总和减少来自不同IDS的重复警报是分布式IDS研究领域中最重要的问题之一。本文提出了一种由本地组件和网络组件组成的分布式警报聚合模型。本地组件将源自传统IDS的原始警报转换为统一格式的基于IDMEF的警报,并将其发送到网络组件。网络组件使用基于类别和功能相似性的聚合算法将类似的警报汇总到一个元警报中。基于订阅的通信机制是这样的,并且还提出了多种消息,以满足组件之间的通信需求,并在整个网络中实现信息共享。 DARPA99数据集上的实验表明了该模型的有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号