A Probabilistic-Based Framework for INFOSEC Alert Correlation
نویسنده
چکیده
To my dear family: Thank you for all of your love, support and encouragements. iii ACKNOWLEDGEMENTS I would like to express my sincere and deep gratitude to my advisor, Dr. Wenke Lee, for his great support, guidance, patience and encouragement during the past several years. Wenke has not only guided and helped me on my research work, but also taught me important values of life. He can always directly point out my weakness that I need to overcome and also always give me cheers when I have achievedf milestones. The thesis would not have been possible without help of Wenke and many other people. I would also like to thank Dr. for their great help on my research and bringing me the wonderful and enjoyable graduate student life at Tech. I will never forget our discussions on ideas, collaborations on research, travels on conferences and wonderful chats on fun. Special thanks to David Dagon. David is an energetic researcher, also like an elder brother, helping us on everything that he can, patiently, warmly and unselfishly. I believe each of the team members will become a super star in the InfoSec community. iv Symons for mentoring me during my summer internship at HP Labs. Many thanks to Dr. Fengmin Gong at McAfee for being my mentor and bringing me to the information security field during my internship at MCNC. Finally, I would like to dedicate this dissertation to my family: my parents, my wife and my brother. I would never have made it through the whole Ph.D. process without their priceless love, encouragements and support. Special thanks to my wife for her great love, patience and understanding during the past several years. She has shared the hardship that I have endured and enjoyed the success that I have achieved. Thank you, my dear family! v TABLE OF CONTENTS
منابع مشابه
A Mission-Impact-Based Approach to INFOSEC Alarm Correlation
We describe a mission-impact-based approach to the analysis of security alerts produced by spatially distributed heterogeneous information security (INFOSEC) devices, such as firewalls, intrusion detection systems, authentication services, and antivirus software. The intent of this work is to deliver an automated capability to reduce the time and cost of managing multiple INFOSEC devices throug...
متن کاملStatistical Causality Analysis of INFOSEC Alert Data
With the increasingly widespread deployment of security mechanisms, such as firewalls, intrusion detection systems (IDSs), antivirus software and authentication services, the problem of alert analysis has become very important. The large amount of alerts can overwhelm security administrators and prevent them from adequately understanding and analyzing the security state of the network, and init...
متن کاملAre Deeper Levels of Risk Analysis a Requirement for Enabling Optimal Tactical Responses in INFOSEC Alert Correlation Systems?
As network speeds and complexities increase, the development of automated systems that enact optimal tactical responses will be required. INFOSEC (information security) alert correlation systems provide a natural home for such capabilities. It can be asked whether the current generation of these systems has the technical capabilities required to enact optimal tactical responses. Specifically, i...
متن کاملProbabilistic Alert Correlation
With the growing deployment of host and network intrusion detection systems, managing reports from these systems becomes critically important. We present a probabilistic approach to alert correlation, extending ideas from multisensor data fusion. Features used for alert correlation are based on alert content that anticipates evolving IETF standards. The probabilistic approach provides a unified...
متن کاملReal-Time intrusion detection alert correlation and attack scenario extraction based on the prerequisite consequence approach
Alert correlation systems attempt to discover the relations among alerts produced by one or more intrusion detection systems to determine the attack scenarios and their main motivations. In this paper a new IDS alert correlation method is proposed that can be used to detect attack scenarios in real-time. The proposed method is based on a causal approach due to the strength of causal methods in ...
متن کامل