Skip to Main Content (Press Enter)

Logo UNIMORE
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNIMORE

|

UNI-FIND

unimore.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Professioni
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

Multistep attack detection and alert correlation in intrusion detection systems

Contributo in Atti di convegno
Data di Pubblicazione:
2011
Citazione:
Multistep attack detection and alert correlation in intrusion detection systems / Manganiello, Fabio; Marchetti, Mirco; Colajanni, Michele. - STAMPA. - 200:(2011), pp. 101-110. ( 2011 International Conference on Information Security and Assurance, ISA 2011 Brno, cze 2011-August) [10.1007/978-3-642-23141-4_10].
Abstract:
A growing trend in the cybersecurity landscape is repre-sented by multistep attacks that involve multiple correlated intrusionactivities to reach the intended target. The duty of correlating secu-rity alerts and reconstructing complete attack scenarios is left to sys-tem administrators because current Network Intrusion Detection Sys-tems (NIDS) are still oriented to generate alerts related to single attacks,with no or minimal correlation analysis among dierent security alerts.We propose a novel approach for the automatic analysis of multiple se-curity alerts generated by state-of-the-art signature-based NIDS. Ourproposal is able to group security alerts that are likely to belong to thesame attack scenario, and to identify correlations and causal relation-ships among them. This goal is achieved by combining alert classicationthrough Self Organizing Maps and unsupervised clustering algorithms.The ecacy of the proposal is demonstrated through a prototype testedagainst network trac traces containing multistep attacks.
Tipologia CRIS:
Relazione in Atti di Convegno
Keywords:
Network security; machine learning; neural networks; alert cluster- ing; alert correlation; Self-Organizing Maps
Elenco autori:
Manganiello, Fabio; Marchetti, Mirco; Colajanni, Michele
Autori di Ateneo:
MARCHETTI Mirco
Link alla scheda completa:
https://iris.unimore.it/handle/11380/768994
Link al Full Text:
https://iris.unimore.it//retrieve/handle/11380/768994/661450/isa2011.pdf
Titolo del libro:
Information Security and Assurance
Pubblicato in:
COMMUNICATIONS IN COMPUTER AND INFORMATION SCIENCE
Journal
COMMUNICATIONS IN COMPUTER AND INFORMATION SCIENCE
Series
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.0.0