Dissertation > Excellent graduate degree dissertation topics show

The Study on False Alarm Filtration and Attack Scenario Recognition of Intrusion Detection System

Author: WangChengMing
Tutor: HuLiang
School: Jilin University
Course: Network and Information Security
Keywords: Intrusion Detection Attack scenarios Hidden Markov Models Conditional Random Fields
CLC: TP393.08
Type: Master's thesis
Year: 2010
Downloads: 96
Quote: 0
Read: Download Dissertation

Abstract


With the continuous development of Internet technology , web - based attacks have continued to increase . The scene of the attack is the attacker from the detection of the target system or network to eventually reach the invasion target a series of attacks , identify and show the attack scene can provide managers with an intuitive understanding of the real intrusion then targeted prevention . The majority of the intrusion detection system is only a single-step attack alarm and contains a large number of false positives , makes a real attack scenes information mixed in a large number of false alarms , makes it difficult to use artificial way to identify the attack scene . An attack scene recognition and visualization methods is elaborated on the basis of intrusion detection system to solve the main problem with the classification problems analogy . The method identified by snort alarm filtering and analysis from the attack scene , and the use of attack graphs show the attack scene . The difficulties caused by the attack scene recognition for snort false positives , false alarm filtering method based on a statistical model and introduced the method of two statistical models . Training and test data , the data set of DARPA2000 snort in alarm sequence the attack scene marked and simulate multiple attack scenarios based . Finally , by comparing experimental comparison of two statistical models in false positives filter effect , and to test the effect of the attack scene recognition . The experimental results show that a large number of false positives filter filter based on a statistical model of false positives , making the attack scene recognition and a method of presenting the scene of the attack can be identified in the test data and draw out a major attack steps in the attack scene and attack details .

Related Dissertations

  1. Research on Intrusion Detection Technology of Wireless Sensor Networks Based on Behavior Trust,TP212.9
  2. Association rule mining based Intrusion Detection System Research and Implementation,TP393.08
  3. The Research on Intrusion Detection System Based on Machine Learning,TP393.08
  4. Integration of Spatial Information Bag of Feature in Image Annotation,TP391.41
  5. An Intrusion Detection System for High-Speed Networks,TP393.08
  6. Sensitivity Analysis and Application of Orthogonal Weight Function Neural Network,TP183
  7. The Study of Intelligent Intrusion Detection System Based on Neural Network in Linux,TP393.08
  8. Petri net -based network intrusion detection system Research and Implementation,TP393.08
  9. Moving target trajectory based recognition system for human-computer interaction,TP391.41
  10. IPv4-IPv6 transition technologies CIDF Based Intrusion Detection System,TP393.08
  11. Intrusion detection based on data mining technology research,TP393.08
  12. Mechanisms based on trust metrics Research and Implementation of Intrusion Detection System,TP393.08
  13. Research and Implementation of Time Series Classification Based on Semi-supervised Learning,TP181
  14. Research on Intrusion Detection Based on Protocol Analysis and Immune Principle,TP393.08
  15. Design and implementation of intrusion detection system based on association rules,TP393.08
  16. CUSUM algorithm based on improved DNS cache attack detection,TP393.08
  17. Web optimization methods for monitoring of sensitive information,TP393.08
  18. The System Study and Design of Active Infrared Intrusion Detection,TN215
  19. The Research of Network Intrusion Detection System in Campus LAN,TP393.08
  20. The Design of Campus Network Distributed Intrusion Detection System Based on Snort,TP393.08
  21. Comprehensive host -based firewalls and intrusion detection security system,TP393.08

CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > Computer Network Security
© 2012 www.DissertationTopic.Net  Mobile