Title
A Multi-Sensor Model to Improve Automated Attack Detection
Abstract
Most intrusion detection systems available today are using a single audit source for detection, even though attacks have distinct manifestations in different parts of the system. In this paper we investigate how to use the alerts from several audit sources to improve the accuracy of the intrusion detection system (IDS). Concentrating on web server attacks, we design a theoretical model to automatically reason about alerts from different sensors, thereby also giving security operators a better understanding of possible attacks against their systems. Our model takes sensor status and capability into account, and therefore enables reasoning about the absence of expected alerts. We require an explicit model for each sensor in the system, which allows us to reason about the quality of information from each particular sensor and to resolve apparent contradictions in a set of alerts.Our model, which is built using Bayesian networks, needs some initial parameter values that can be provided by the IDS operator. We apply this model in two different scenarios for web server security. The scenarios show the importance of having a model that dynamically can adapt to local transitional traffic conditions, such as encrypted requests, when using conflicting evidence from sensors to reason about attacks.
Year
DOI
Venue
2008
10.1007/978-3-540-87403-4_16
RAID
Keywords
Field
DocType
different sensor,different part,ids operator,multi-sensor model,sensor status,explicit model,particular sensor,improve automated attack detection,theoretical model,different scenario,audit source,intrusion detection system,quality of information,intrusion detection,bayesian network
Host-based intrusion detection system,Computer science,Computer security,Encryption,Anomaly-based intrusion detection system,Real-time computing,Bayesian network,Operator (computer programming),Intrusion detection system,Information quality,Web server
Conference
Volume
ISSN
Citations 
5230
0302-9743
10
PageRank 
References 
Authors
0.76
17
3
Name
Order
Citations
PageRank
Magnus Almgren127039.17
Ulf Lindqvist215618.48
Erland Jonsson355663.09