Handling Alerts for Intrusion Detection System Using Stateful Pattern Matching

被引:0
|
作者
Chakir, El Mostapha [1 ]
Idrissi Khamlichi, Youness [2 ]
Moughit, Mohamed [1 ]
机构
[1] Univ Hassan First Settat, Fac Sci & Technol, Mobil & Modeling IR2M, Lab Comp Networks, Settat, Morocco
[2] Univ Sidi Mohamed Ben Abdellah, Natl Sch Appl Sci, Mobil & Modeling IR2M, Lab Comp Networks, Fes, Morocco
关键词
Intrusion Detection System; false positive; false negative; Snort; alert processing; Pattern Matching; DARPA KDD cup 99;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Over the years, network intrusion detection systems have evolved to handle varying types of threats. These days, network managers expect network intrusion detection systems (IDS) to detect attacks and include anomaly-awareness, in addition to handling older threats that haven't disappeared. Researchers have proposed different methods and algorithms to improve intrusion detection systems (IDS). There are different types of these systems, most of them are capable of detecting many attacks, but cannot provide a clear idea to the analyst because of the huge number of the false alerts generated by these systems. This weakness has led to the emergence of many methods in which to deal with these alerts. The aim of conducted research in this field is to propose a new technique to handle the alerts, to reduce them and distinguish real attacks from false alerts and low importance events. In this paper a new alert classification algorithm for IDS proposed, that uses the Pattern Matching. The proposed algorithm reduces alerts and distinguishes serious alerts, low importance and irrelevant one with a high performance. By the experimental results on DARPA KDD cup 99 Dataset the system is able to classify alerts and causes reducing false alerts considerably.
引用
收藏
页码:139 / 144
页数:6
相关论文
共 50 条
  • [1] A Survey of Pattern Matching Algorithm in Intrusion Detection System
    Gharaee, Hossein
    Seifi, Shokoufeh
    Monsefan, Nima
    [J]. 2014 7th International Symposium on Telecommunications (IST), 2014, : 946 - 953
  • [2] An Improved Pattern Matching Algorithm in the Intrusion Detection System
    Zhang Ping
    Liu Jianghui
    [J]. MEASURING TECHNOLOGY AND MECHATRONICS AUTOMATION, PTS 1 AND 2, 2011, 48-49 : 203 - +
  • [3] A pattern matching based network intrusion detection system
    Zhou Chunyue
    Liu Yun
    Zhang Hongke
    [J]. 2006 9TH INTERNATIONAL CONFERENCE ON CONTROL, AUTOMATION, ROBOTICS AND VISION, VOLS 1- 5, 2006, : 1410 - +
  • [4] Memory Efficacious Pattern Matching Intrusion Detection System
    Dhivya, S.
    Dhakchianandan, D.
    Gowtham, A.
    Sujatha, Kola P.
    Kannan, A.
    [J]. 2013 INTERNATIONAL CONFERENCE ON RECENT TRENDS IN INFORMATION TECHNOLOGY (ICRTIT), 2013, : 652 - 656
  • [5] Research on Efficient Pattern Matching Algorithms in Intrusion Detection System
    Liu-xiaoxing
    Yu-ning
    [J]. 2014 7TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION (ICICTA), 2014, : 509 - 512
  • [6] Research of pattern matching in intrusion detection
    Huang, JC
    Tian, JF
    Du, RZ
    Zhai, JQ
    [J]. 2003 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-5, PROCEEDINGS, 2003, : 1877 - 1882
  • [7] High-performance stateful intrusion detection system
    Yoon, Seungyong
    Kim, Byoungkoo
    Oh, Jintae
    [J]. 2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 574 - 579
  • [8] Variable Length Pattern Matching for Hardware Network Intrusion Detection System
    Xue, Chun Jason
    Liu, Meilin
    Zhuge, QingFeng
    Sha, Edwin Hsing-Mean
    [J]. JOURNAL OF SIGNAL PROCESSING SYSTEMS FOR SIGNAL IMAGE AND VIDEO TECHNOLOGY, 2010, 59 (01): : 85 - 93
  • [9] Pattern Matching Algorithms for Intrusion Detection and Prevention System: A Comparative Analysis
    Gupta, Vibha
    Singh, Maninder
    Bhalla, Vinod K.
    [J]. 2014 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2014, : 50 - 54
  • [10] The Research and Amelioration of Pattern-matching Algorithm in Intrusion Detection System
    Wu, Pei-fei
    Shen, Hai-juan
    [J]. 2012 IEEE 14TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS & 2012 IEEE 9TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (HPCC-ICESS), 2012, : 1712 - 1715