AIDA Framework: Real-Time Correlation and Prediction of Intrusion Detection Alerts

被引:12
|
作者
Husak, Martin [1 ]
Kaspar, Jaroslav [1 ]
机构
[1] Masaryk Univ, Inst Comp Sci, Brno, Czech Republic
关键词
intrusion detection; information sharing; alert correlation; prediction; data mining;
D O I
10.1145/3339252.3340513
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present AIDA, an analytical framework for processing intrusion detection alerts with a focus on alert correlation and predictive analytics. The framework contains components that filter, aggregate, and correlate the alerts, and predict future security events using the predictive rules distilled from historical records. The components are based on stream processing and use selected features of data mining (namely sequential rule mining) and complex event processing. The framework was deployed as an analytical component of an alert sharing platform, where alerts from intrusion detection systems, honeypots, and other data sources are exchanged among the community of peers. The deployment is briefly described and evaluated to illustrate the capabilities of the framework in practice. Further, the framework may be deployed locally for experimentations over datasets.
引用
收藏
页数:8
相关论文
共 50 条
  • [1] Real-time analysis of intrusion detection alerts via correlation
    Lee, Soojin
    Chung, Byungchun
    Kim, Heeyoul
    Lee, Yunho
    Park, Chanil
    Yoon, Hyunsoo
    COMPUTERS & SECURITY, 2006, 25 (03) : 169 - 183
  • [2] Real-time correlation of network security alerts
    Li, Zhitang
    Zhang, Aifang
    Lei, Jie
    Wang, Li
    ICEBE 2007: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2007, : 73 - +
  • [3] Real-Time Attack Scenario Detection via Intrusion Detection Alert Correlation
    Zali, Zeinab
    Hashemi, Massoud Reza
    Saidi, Hossein
    2012 9TH INTERNATIONAL ISC CONFERENCE ON INFORMATION SECURITY AND CRYPTOLOGY (ISCISC), 2012, : 95 - 102
  • [4] IDSRadar:a real-time visualization framework for IDS alerts
    ZHAO Ying
    ZHOU FangFang
    FAN XiaoPing
    LIANG Xing
    LIU YongGang
    Science China(Information Sciences), 2013, 56 (08) : 216 - 227
  • [5] IDSRadar: a real-time visualization framework for IDS alerts
    Zhao Ying
    Zhou FangFang
    Fan XiaoPing
    Liang Xing
    Liu YongGang
    SCIENCE CHINA-INFORMATION SCIENCES, 2013, 56 (08) : 1 - 12
  • [6] IDSRadar: a real-time visualization framework for IDS alerts
    Ying Zhao
    FangFang Zhou
    XiaoPing Fan
    Xing Liang
    YongGang Liu
    Science China Information Sciences, 2013, 56 : 1 - 12
  • [7] CONDITIONAL RANDOM FIELDS BASED REAL-TIME INTRUSION DETECTION FRAMEWORK
    Gu, Jiaojiao
    Jiang, Wenzhi
    Hu, Wenxuan
    Zhang, Xiaoyu
    3RD INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY AND COMPUTER SCIENCE (ITCS 2011), PROCEEDINGS, 2011, : 186 - 189
  • [8] Improving the Quality of Alerts with Correlation in Intrusion Detection
    Salim, Lalla Fatima
    Mezrioui, Abdellatif
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2007, 7 (12): : 210 - 215
  • [9] Modeling network intrusion detection alerts for correlation
    Zhou, Jingmin
    Heckman, Mark
    Reynolds, Brennen
    Carlson, Adam
    Bishop, Matt
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2007, 10 (01)
  • [10] Robust Real-time Intrusion Detection System
    Kim, Byung-Joo
    Kim, Il-Kon
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2005, 1 (01): : 9 - 13