RISS 학술연구정보서비스

검색
다국어 입력

http://chineseinput.net/에서 pinyin(병음)방식으로 중국어를 변환할 수 있습니다.

변환된 중국어를 복사하여 사용하시면 됩니다.

예시)
  • 中文 을 입력하시려면 zhongwen을 입력하시고 space를누르시면됩니다.
  • 北京 을 입력하시려면 beijing을 입력하시고 space를 누르시면 됩니다.
닫기
    인기검색어 순위 펼치기

    RISS 인기검색어

      KCI등재

      A Skyline Based False Alarm Reduction in Intrusion Detection Systems

      한글로보기

      https://www.riss.kr/link?id=A104302532

      • 0

        상세조회
      • 0

        다운로드
      서지정보 열기
      • 내보내기
      • 내책장담기
      • 공유하기
      • 오류접수

      부가정보

      다국어 초록 (Multilingual Abstract)

      Recent expansion of the Internet has caused to emerge lots of malicious threats. Though various Intrusion Detection Systems (IDSs) have been proposed so far, none of them has completely coped with the emerged issues. Once IDS finishes its performance,...

      Recent expansion of the Internet has caused to emerge lots of malicious threats. Though various Intrusion Detection Systems (IDSs) have been proposed so far, none of them has completely coped with the emerged issues. Once IDS finishes its performance, lots of false alarms can be produced, which can lead to increasing burden in network administrator's work. Therefore, it is necessary to have a system for post-processing of the false alarms that can operate after intrusion detection process finishes its work, and divide false alarms into secure data packets and attacks. In this paper, we propose to select only top-k false alarms that pose a threat to the system. Our approach is to formulate the existing issue as a selection problem with which skyline queries can handle fast and efficiently. In this paper, we utilize Sort-Filter-Skyline (SFS) algorithm that constructs skylines by finding only such data points that are not dominated by other data points. In the context of the proposed method, we perform a skyline operation on false alarms, and extract alarms that are not dominated by other alarms. These alarms are potential candidates to become secure data packets or attacks. Experiments show that the proposed method outperforms other methods on reducing false positive and false negative, while maintaining the acceptable computational time and memory usage.

      더보기

      참고문헌 (Reference)

      1 Brumley D, "Towards Automatic Generation of Vulnerability-Based Signatures" 2-16, 2006

      2 Chomicki, J, "Skyline with presorting" 717-719, 2003

      3 Viinikka J, "Processing intrusion detection alert aggregates with time series modeling" 312-324, 2009

      4 Hassani M, "Network Intrusion Detection using a Secure Ranking of Hidden Outliers" 1-10, 2011

      5 Tajbakhsh, R, "Intrusion detection using fuzzy association rules" 9 : 462-469, 2009

      6 Treinen J.J, "Finding The Needle: Suppression of False Alarms in Large Intrusion Detection Data Sets" 237-244, 2009

      7 Julisch K, "Clustering Intrusion Detection Alarms to Support Root Cause Analysis" 443-471, 2003

      8 Bolzoni D, "ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems" (1-12) : 2007

      1 Brumley D, "Towards Automatic Generation of Vulnerability-Based Signatures" 2-16, 2006

      2 Chomicki, J, "Skyline with presorting" 717-719, 2003

      3 Viinikka J, "Processing intrusion detection alert aggregates with time series modeling" 312-324, 2009

      4 Hassani M, "Network Intrusion Detection using a Secure Ranking of Hidden Outliers" 1-10, 2011

      5 Tajbakhsh, R, "Intrusion detection using fuzzy association rules" 9 : 462-469, 2009

      6 Treinen J.J, "Finding The Needle: Suppression of False Alarms in Large Intrusion Detection Data Sets" 237-244, 2009

      7 Julisch K, "Clustering Intrusion Detection Alarms to Support Root Cause Analysis" 443-471, 2003

      8 Bolzoni D, "ATLANTIDES: An Architecture for Alert Verification in Network Intrusion Detection Systems" (1-12) : 2007

      더보기

      동일학술지(권/호) 다른 논문

      분석정보

      View

      상세정보조회

      0

      Usage

      원문다운로드

      0

      대출신청

      0

      복사신청

      0

      EDDS신청

      0

      동일 주제 내 활용도 TOP

      더보기

      주제

      연도별 연구동향

      연도별 활용동향

      연관논문

      연구자 네트워크맵

      공동연구자 (7)

      유사연구자 (20) 활용도상위20명

      인용정보 인용지수 설명보기

      학술지 이력

      학술지 이력
      연월일 이력구분 이력상세 등재구분
      2026 평가예정 재인증평가 신청대상 (재인증)
      2020-01-01 평가 등재학술지 유지 (재인증) KCI등재
      2017-01-01 평가 등재학술지 유지 (계속평가) KCI등재
      2013-01-01 평가 등재학술지 유지 (등재유지) KCI등재
      2010-01-01 평가 등재학술지 선정 (등재후보2차) KCI등재
      2009-01-01 평가 등재후보 1차 PASS (등재후보1차) KCI등재후보
      2007-01-01 평가 등재후보학술지 선정 (신규평가) KCI등재후보
      더보기

      학술지 인용정보

      학술지 인용정보
      기준연도 WOS-KCI 통합IF(2년) KCIF(2년) KCIF(3년)
      2016 0.02 0.02 0.01
      KCIF(4년) KCIF(5년) 중심성지수(3년) 즉시성지수
      0.02 0.02 0.183 0.03
      더보기

      이 자료와 함께 이용한 RISS 자료

      나만을 위한 추천자료

      해외이동버튼