A knowledge-based alert evaluation and security decision support framework

被引:0
|
作者
Yu, JQ [1 ]
Reddy, R [1 ]
Selliah, S [1 ]
Reddy, S [1 ]
机构
[1] Illinois Wesleyan Univ, Dept Math & Comp Sci, Bloomington, IL 61701 USA
关键词
IDS; vulnerability; alert management; security decision support; alert correlation;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, a generic architecture for intrusion alert management, analysis and security decision support is described. The architecture is composed of four components: (1)Alert Aggregator, (2)Alert Evaluation and Security Decision Support Component, (3)Alert Correlator and (4)Synthetic Alert Report Generator. The core of this architecture is the Alert Evaluation and Security Decision Support component. The component provides a framework for knowledge-based alert evaluation and security decision support. The framework aims at reducing alert overload and false positive alerts, prioritizing alerts and providing real-time security decision support. This is accomplished by integrating knowledge of the protected network and host asset information and knowledge of known vulnerability requirements as well as specified security policies into the alert evaluation process. The alert evaluation and security decision support component as well as the alert aggregator have been implemented, and the implementation results are presented in this paper.
引用
收藏
页码:194 / 200
页数:7
相关论文
共 50 条
  • [21] Confluence™: Knowledge-Based Decision Support In Complex Missions
    De, Piali
    Jennings, Daniel
    Sperry, David
    2009 IEEE CONFERENCE ON TECHNOLOGIES FOR HOMELAND SECURITY, 2009, : 553 - 560
  • [22] Road Safety Knowledge-Based Decision Support System
    Dell'Acqua, Gianluca
    De Luca, Mario
    Mauro, Raffaele
    STATE OF THE ART IN THE EUROPEAN QUANTITATIVE ORIENTED TRANSPORTATION AND LOGISTICS RESEARCH, 2011: 14TH EURO WORKING GROUP ON TRANSPORTATION & 26TH MINI EURO CONFERENCE & 1ST EUROPEAN SCIENTIFIC CONFERENCE ON AIR TRANSPORT, 2011, 20
  • [23] Knowledge-based multi-criteria decision support
    Zopounidis, Constantin
    EUROPEAN JOURNAL OF OPERATIONAL RESEARCH, 2009, 195 (03) : 827 - 828
  • [24] KNOWLEDGE-BASED APPROACH TO MODULAR CONSTRUCTION DECISION SUPPORT
    MURTAZA, MB
    FISHER, DJ
    SKIBNIEWSKI, MJ
    JOURNAL OF CONSTRUCTION ENGINEERING AND MANAGEMENT-ASCE, 1993, 119 (01): : 115 - 130
  • [25] KNOWLEDGE-BASED DECISION SUPPORT IN BUSINESS - ISSUES AND A SOLUTION
    DHAR, V
    CROKER, A
    IEEE EXPERT-INTELLIGENT SYSTEMS & THEIR APPLICATIONS, 1988, 3 (01): : 53 - 62
  • [26] Knowledge-based decision support for the improvement of standard products
    Abramovici, Michael
    Lindner, Andreas
    CIRP ANNALS-MANUFACTURING TECHNOLOGY, 2013, 62 (01) : 159 - 162
  • [27] KNOWLEDGE-BASED DECISION SUPPORT SYSTEM FOR ACCOUNTING AUDITORS
    MAROSE, RA
    ROTHENBERG, D
    SANKARAN, S
    IFIP TRANSACTIONS A-COMPUTER SCIENCE AND TECHNOLOGY, 1992, 9 : 201 - 213
  • [29] Knowledge-based decision support system for site selecting
    School of Resources and Environment Science, Wuhan University, 129 Luoyu Road, Wuhan 430079, China
    不详
    不详
    Geomatics Inf. Sci. Wuhan Univ., 2008, 2 (149-152): : 149 - 152
  • [30] SUSTAINABLE AGRICULTURAL DEVELOPMENT: KNOWLEDGE-BASED DECISION SUPPORT
    Kurlavicius, Algimantas
    TECHNOLOGICAL AND ECONOMIC DEVELOPMENT OF ECONOMY, 2009, 15 (02) : 294 - 309