@inproceedings{170e595bc22a47868705232b823a48f2,
title = "A language driven intrusion detection system for event and alert correlation",
abstract = "It is well known that security prevention mechanisms are not sufficient to protect efficiently an information system. Intrusion detection systems are required. But these systems present many imperfections. In particular, they can either generate false positives (i.e., alarms that should not be produced) or miss attacks (false negatives). However, the main problem is the generation of false positives that can overwhelm the information system administrator. In this paper, we follow the notion of correlation proposed by others. The objective is to aim at correlating either events in the analyser or alerts in the manager. We first present the ADeLe language, which provides a way to define the correlation properties. Then we present which algorithms have been carried out in our IDS to handle ADeLe signatures. Finally, we show the stress tests that have been applied to the probe algorithms that we have implemented.",
keywords = "Alert correlation, Attack signature recognition, Event correlation, Intrusion detection, Site security monitoring",
author = "Eric Totel and Bernard Vivinis and Ludovic M{\'e}",
year = "2004",
month = jan,
day = "1",
doi = "10.1007/1-4020-8143-x\_14",
language = "English",
isbn = "9781475780161",
series = "IFIP Advances in Information and Communication Technology",
publisher = "Springer New York LLC",
pages = "209--224",
booktitle = "Security and Protection in Information Processing systems - IFIP 18th World Computer Congress, TC11 19th International Information Security Conference, SEC 2004",
note = "IFIP TC11 19th International Information Security Conference, SEC 2004 ; Conference date: 22-08-2004 Through 27-08-2004",
}