A language driven intrusion detection system for event and alert correlation

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

It is well known that security prevention mechanisms are not sufficient to protect efficiently an information system. Intrusion detection systems are required. But these systems present many imperfections. In particular, they can either generate false positives (i.e., alarms that should not be produced) or miss attacks (false negatives). However, the main problem is the generation of false positives that can overwhelm the information system administrator. In this paper, we follow the notion of correlation proposed by others. The objective is to aim at correlating either events in the analyser or alerts in the manager. We first present the ADeLe language, which provides a way to define the correlation properties. Then we present which algorithms have been carried out in our IDS to handle ADeLe signatures. Finally, we show the stress tests that have been applied to the probe algorithms that we have implemented.

Original languageEnglish
Title of host publicationSecurity and Protection in Information Processing systems - IFIP 18th World Computer Congress, TC11 19th International Information Security Conference, SEC 2004
PublisherSpringer New York LLC
Pages209-224
Number of pages16
ISBN (Print)9781475780161
DOIs
Publication statusPublished - 1 Jan 2004
Externally publishedYes
EventIFIP TC11 19th International Information Security Conference, SEC 2004 - Toulouse, France
Duration: 22 Aug 200427 Aug 2004

Publication series

NameIFIP Advances in Information and Communication Technology
Volume147
ISSN (Print)1868-4238

Conference

ConferenceIFIP TC11 19th International Information Security Conference, SEC 2004
Country/TerritoryFrance
CityToulouse
Period22/08/0427/08/04

Keywords

  • Alert correlation
  • Attack signature recognition
  • Event correlation
  • Intrusion detection
  • Site security monitoring

Fingerprint

Dive into the research topics of 'A language driven intrusion detection system for event and alert correlation'. Together they form a unique fingerprint.

Cite this