A knowledge-based alert evaluation and security decision support framework

被引:0
|
作者
Yu, JQ [1 ]
Reddy, R [1 ]
Selliah, S [1 ]
Reddy, S [1 ]
机构
[1] Illinois Wesleyan Univ, Dept Math & Comp Sci, Bloomington, IL 61701 USA
关键词
IDS; vulnerability; alert management; security decision support; alert correlation;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
In this paper, a generic architecture for intrusion alert management, analysis and security decision support is described. The architecture is composed of four components: (1)Alert Aggregator, (2)Alert Evaluation and Security Decision Support Component, (3)Alert Correlator and (4)Synthetic Alert Report Generator. The core of this architecture is the Alert Evaluation and Security Decision Support component. The component provides a framework for knowledge-based alert evaluation and security decision support. The framework aims at reducing alert overload and false positive alerts, prioritizing alerts and providing real-time security decision support. This is accomplished by integrating knowledge of the protected network and host asset information and knowledge of known vulnerability requirements as well as specified security policies into the alert evaluation process. The alert evaluation and security decision support component as well as the alert aggregator have been implemented, and the implementation results are presented in this paper.
引用
收藏
页码:194 / 200
页数:7
相关论文
共 50 条
  • [1] Knowledge-Based Decision Support System for Emergency Management: The Pandemic Framework
    Masmas, Bahaa Ahmad
    Mohamed, Azlinah
    [J]. JOURNAL OF INFORMATION AND COMMUNICATION TECHNOLOGY-MALAYSIA, 2021, 20 (04): : 599 - 628
  • [2] The Conceptual MADE Framework for Pervasive and Knowledge-Based Decision Support in Telemedicine
    Fung, Nick L. S.
    Jones, Valerie M.
    Widya, Ing
    Broens, Tom H. F.
    Larburu, Nekane
    Bults, Richard G. A.
    Shalom, Erez
    Hermens, Hermie J.
    [J]. INTERNATIONAL JOURNAL OF KNOWLEDGE AND SYSTEMS SCIENCE, 2016, 7 (01)
  • [3] A knowledge-based framework enabling decision support in RFID solutions for healthcare
    Ruta, Michele
    Scioscia, Floriano
    Di Sciascio, Eugenio
    Scioscia, Crescenzio
    [J]. IEEE INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE 2010), 2010, : 1983 - 1988
  • [4] Knowledge-Based Decision Support System
    史忠植
    [J]. Journal of Computer Science & Technology, 1987, (01) : 22 - 29
  • [5] MULTIPERSPECTIVE KNOWLEDGE-BASED DECISION SUPPORT
    HAWGOOD, J
    [J]. JOURNAL OF THE OPERATIONAL RESEARCH SOCIETY, 1987, 38 (12) : 1201 - 1201
  • [6] Knowledge-based decision support by CRITIC
    Xiang, WN
    [J]. ENVIRONMENT AND PLANNING B-PLANNING & DESIGN, 1997, 24 (01): : 69 - 79
  • [7] A Fuzzy Knowledge-based Decision Support System for Tender Call Evaluation
    Alexopoulos, Panos
    Wallace, Manolis
    Kafentzis, Konstantinos
    Thomopoulos, Aristodimos
    [J]. ARTIFICIAL INTELLIGENCE APPLICATIONS AND INNOVATIONS III, 2009, : 51 - +
  • [8] Medical Knowledge-Based Decision Support System
    Fomin, Alexey
    Turov, Mikhail
    Matrosova, Elena
    Tikhomirova, Anna
    [J]. BIOLOGICALLY INSPIRED COGNITIVE ARCHITECTURES (BICA) FOR YOUNG SCIENTISTS, 2018, 636 : 324 - 328
  • [9] ISSUES IN KNOWLEDGE-BASED DECISION SUPPORT - COMMENTARY
    HOLLNAGEL, E
    [J]. INTERNATIONAL JOURNAL OF MAN-MACHINE STUDIES, 1987, 27 (5-6): : 743 - 751
  • [10] A METHODOLOGY FOR KNOWLEDGE-BASED SCHEDULING DECISION SUPPORT
    SHAH, VC
    MADEY, GR
    MEHREZ, A
    [J]. OMEGA-INTERNATIONAL JOURNAL OF MANAGEMENT SCIENCE, 1992, 20 (5-6): : 679 - 703