Passer à la navigation principale Passer à la recherche Passer au contenu principal

Response: Bridging the link between intrusion detection alerts and security policies

  • Hervé Debar
  • , Yohann Thomas
  • , Frédéric Cuppens
  • , Nora Cuppens-Boulahia
  • France Télécom RandD
  • ENST Bretagne

Résultats de recherche: Le chapitre dans un livre, un rapport, une anthologie ou une collectionChapitreRevue par des pairs

Résumé

With the deployment of intrusion detection systems has come the question of alert usage. The current trend of intrusion prevention systems provides mechanisms for isolated response, suffering from two important drawbacks. First, the response is applied on a single point of the information system. Second, its application is repeated every time an alert condition is raised. Both drawbacks result in a suboptimal response system, where security is improved at these particular network or host access control points, but where service dependancies are not taken into account. In this paper, we examine a new mechanism for adapting the security policy of an information system according to the threat it receives, and hence its behaviour and the services it offers. This mechanism takes into account not only threats, but also legal constraints and other objectives of the organization operating this information system, taking into account multiple security objectives and providing several trade-off options between security objectives, performance objectives, and other operational constraints. The proposed mechanism bridges the gap between preventive security technologies and intrusion detection, and builds upon existing technologies to facilitate formalization on one hand, and deployment on the other hand.

langue originaleAnglais
titreIntrusion Detection Systems
rédacteurs en chefRoberto Di Pietro, Luigi Mancini
Pages129-170
Nombre de pages42
Les DOIs
étatPublié - 1 déc. 2008
Modification externeOui

Série de publications

NomAdvances in Information Security
Volume38
ISSN (imprimé)1568-2633

Empreinte digitale

Examiner les sujets de recherche de « Response: Bridging the link between intrusion detection alerts and security policies ». Ensemble, ils forment une empreinte digitale unique.

Contient cette citation