Abstract | ||
---|---|---|
In this paper, a generic architecture for intrusion alert management, analysis and security decision support is described. The architecture is composed of four components: (1)Alert Aggregator, (2)Alert Evaluation and Security Decision Support Component, (3)Alert Correlator and (4)Synthetic Alert Report Generator. The core of this architecture is the Alert Evaluation and Security Decision Support component. The component provides a framework for knowledge-based alert evaluation and security decision support. The framework aims at reducing alert overload and false positive alerts, prioritizing alerts and providing real-time security decision support. This is accomplished by integrating knowledge of the protected network and host asset information and knowledge of known vulnerability requirements as well as specified security policies into the alert evaluation process. The alert evaluation and security decision support component as well as the alert aggregator have been implemented, and the implementation results are presented in this paper. |
Year | Venue | Keywords |
---|---|---|
2005 | SAM '05: Proceedings of the 2005 International Conference on Security and Management | IDS,vulnerability,alert management,security decision support,alert correlation |
Field | DocType | Citations |
Data science,Computer security,Computer science,Decision support system | Conference | 0 |
PageRank | References | Authors |
0.34 | 3 | 4 |
Name | Order | Citations | PageRank |
---|---|---|---|
Jinqiao Yu | 1 | 51 | 6.35 |
Y. V. Ramana Reddy | 2 | 69 | 20.35 |
Sentil Selliah | 3 | 42 | 4.14 |
Sumitra Reddy | 4 | 123 | 28.83 |