Strategic Alert Throttling for Intrusion Detection Systems

Computer Science – Neural and Evolutionary Computing

Scientific paper

Rate now

  [ 0.00 ] – not rated yet Voters 0   Comments 0

Details

Scientific paper

Network intrusion detection systems are themselves becoming targets of attackers. Alert flood attacks may be used to conceal malicious activity by hiding it among a deluge of false alerts sent by the attacker. Although these types of attacks are very hard to stop completely, our aim is to present techniques that improve alert throughput and capacity to such an extent that the resources required to successfully mount the attack become prohibitive. The key idea presented is to combine a token bucket filter with a realtime correlation algorithm. The proposed algorithm throttles alert output from the IDS when an attack is detected. The attack graph used in the correlation algorithm is used to make sure that alerts crucial to forming strategies are not discarded by throttling.

No associations

LandOfFree

Say what you really think

Search LandOfFree.com for scientists and scientific papers. Rate them and share your experience with other people.

Rating

Strategic Alert Throttling for Intrusion Detection Systems does not yet have a rating. At this time, there are no reviews or comments for this scientific paper.

If you have personal experience with Strategic Alert Throttling for Intrusion Detection Systems, we encourage you to share that experience with our LandOfFree.com community. Your opinion is very important and Strategic Alert Throttling for Intrusion Detection Systems will most certainly appreciate the feedback.

Rate now

     

Profile ID: LFWR-SCP-O-156313

  Search
All data on this website is collected from public sources. Our data reflects the most accurate information available at the time of publication.