TRINETR: An Intrusion Detection Alert Management System

نویسندگان

  • Jinqiao Yu
  • Y. V. Ramana Reddy
  • Sentil Selliah
  • Kankanahalli Srinivas
  • Sumitra Reddy
  • Vijayanand Bharadwaj
چکیده

TRINETR: An Intrusion Detection Alert Management and Analysis System by Jinqiao Yu Intrusion detection system (IDS) is a software system or hardware device deployed to monitor network and host activities including data flows and information accesses etc. to capture suspicious activities. In recent years, IDS has began to gain wide acceptance as a necessary and worthwhile investment on security. But current IDS products present many flaws including alert flooding, too many false alerts, lack of context awareness and security decision support etc. Many of these problems are severely hindering them from being used more efficiently in practice. To make the use of IDS products more efficient and generated alerts more accurate, this dissertation work an intrusion detection alert management and analysis project, dubbed as TRINETR, has been developed at Concurrent Engineering Research Center of West Virginia University. A novel alert management and analysis architecture is presented in the project. The architecture is composed of three key parts: (1) Alert Aggregation, (2) Knowledge-based Alert Evaluation and Security Decision Support, and (3) Alert Correlation. The project is aimed at reducing alert overload by aggregating alerts from multiple sensors to generate condensed views, reducing false positive alerts by integrating network and host system information into alert evaluation process, providing appropriate security solution suggestion regarding the evaluated alerts to facilitate decision making, and correlating intrusion events based on logical relations among them to generate global and synthesized alert report. Implementation and testing of a prototype system are also reported in this dissertation as well as a study of application of time series analysis approach into alert correlation.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

TRINETR: Facilitating Alerts Analysis and Response Decision Making

Due to many inherent deficiencies and flaws, current intrusion detection systems (IDS) are plagued by numerous problems. Intrusion Detection Systems are often inefficient and ineffective when used alone. IDS products need to be fully integrated into the security defense line. Intrusion alert analysis and management are crucial in achieving this. In this paper, we describe an intrusion detection...

متن کامل

Real-Time intrusion detection alert correlation and attack scenario extraction based on the prerequisite consequence approach

Alert correlation systems attempt to discover the relations among alerts produced by one or more intrusion detection systems to determine the attack scenarios and their main motivations. In this paper a new IDS alert correlation method is proposed that can be used to detect attack scenarios in real-time. The proposed method is based on a causal approach due to the strength of causal methods in ...

متن کامل

Alert correlation and prediction using data mining and HMM

Intrusion Detection Systems (IDSs) are security tools widely used in computer networks. While they seem to be promising technologies, they pose some serious drawbacks: When utilized in large and high traffic networks, IDSs generate high volumes of low-level alerts which are hardly manageable. Accordingly, there emerged a recent track of security research, focused on alert correlation, which ext...

متن کامل

Strategic Management of Security Information through an Entropy-Based Alert Correlator

Strategic Management of Security Information through an Entropy-Based Alert Correlator We present an integrated system to process in real time a huge incoming stream of alerts produced by current intrusion detection systems. A key component of this system includes an unsupervised clustering algorithm that combines a temporal sliding window, entropy tests, and expert rules to track the on-the-fl...

متن کامل

An Intrusion Alert Correlator Based on Prerequisites of Intrusions

Current intrusion detection systems (IDSs) usually focus on detecting low-level attacks and/or anomalies; none of them can capture the logical steps or attack strategies behind these attacks. Consequently, the IDSs usually generate a large amount of alerts. In situations where there are intensive intrusive actions, not only will actual alerts be mixed with false alerts, but the amount of alerts...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2004