Correlation of intrusion symptoms: An application of chronicles

Research output: Chapter in Book/Report/Conference proceedingChapterpeer-review

Abstract

In this paper, we propose a multi-alarm misuse correlation component based on the chronicles formalism. Chronicles provide a high level declarative language and a recognition system that is used in other areas where dynamic systems are monitored. This formalism allows us to reduce the number of alarms shipped to the operator and enhances the quality of the diagnosis provided.

Original languageEnglish
Title of host publicationLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
EditorsGiovanni Vigna, Christopher Kruegel, Erland Jonsson, Christopher Kruegel
PublisherSpringer Verlag
Pages94-112
Number of pages19
ISBN (Print)3540408789, 9783540408789
DOIs
Publication statusPublished - 1 Jan 2003
Externally publishedYes

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume2820
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Fingerprint

Dive into the research topics of 'Correlation of intrusion symptoms: An application of chronicles'. Together they form a unique fingerprint.

Cite this