Title
A Flexible, High Performance Service-Oriented Architecture for Detecting Cyber Attacks
Abstract
A high percentage of false positives remains a problem in current network security detection systems. With the growing reliance of industry on computer networks, and the growing variety of attacks that can be directed towards a computer network, it is clear that detection systems must be improved in order to tackle this growing problem. To help minimise the problem of false positives, this paper describes a method and apparatus for security alert analysis that is based on two technologies: (i) event correlation and (ii) a truth maintenance system. This work was undertaken in the context of practical network security management in a large outsourced management service provider in the Asia-Pacific region.
Year
DOI
Venue
2008
10.1109/HICSS.2008.19
HICSS
Keywords
Field
DocType
data security,information security,algorithm design and analysis,service provider,false positive,event correlation,network security,intrusion detection,service oriented architecture,computer network,logic,secure computation
Data security,Computer security,Computer science,Network security,Information security,Service provider,Security service,Intrusion detection system,Service-oriented architecture,False positive paradox
Conference
ISBN
Citations 
PageRank 
0-7695-3075-8
7
0.72
References 
Authors
5
5
Name
Order
Citations
PageRank
Adam Wynne1689.41
Ian Gorton21488134.37
Justin Almquist3425.88
Jack Chatterton4222.97
Dave Thurman5142.14