FREE Registration is required
Overview:
Correlation and fusion of intrusion alerts to provide effective Situation Awareness of cyber-attacks has become an active area of research. Snort is the most widely deployed intrusion detection sensor. For many networks and their system administrators, the alerts generated by Snort are the primary indicators of network misuse and attacker activity. However, the volume of the alerts generated in typical networks makes real-time attack scenario comprehension dif-cult. This paper present an attack-stage oriented classification of alerts using Snort as an example, and demonstrate that this effectively improves real-time Situation Awareness of multistage attacks. It also incorporate this scheme into a real-time attack detection framework and prototype presented by the authors in previous work and provide some results from testing against multistage attack scenarios.
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 143 KB | |
| Date: | Dec 2007 | ||
| Pages: | 6 |
People who downloaded this item also downloaded
![]() |
Phone interview cheat sheet |
Top results from Security Tools
White Papers, Webcasts, and Resources
- The Essential Guide: Real-Time High Availability for Exchange - Replicate Exchange Data for Improved Resiliency CA XOsoftSurvive major interruptions to your Exchange environment--and improve its resiliency and availability--with a real-time data replication solution.
- Best Practices in the Call Center: A Customer Touch-Point Methodology OracleImprove customer satisfaction in your contact center -- while reducing costs -- with an approach that puts all client touch-points on one continuum.
- Microsoft SharePoint Performance Brief RiverbedSee how Riverbed WAN optimization solutions made SharePoint perform up to 44 times faster, while slashing bandwidth utilization up to 99%.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
Featured Training Courses
Meet Doc
-
Here to help you with your Document Management Needs
- Doc is an enigma. Born to a Russian ballerina and a German electrical engineer, he grew up in various locations in the United States. He’s seen the insides of more brands, versions, and generations of printer and printer-related hardware than almost anyone.
- To learn more about this mysterious figure check out his blog on ZDNet and his Workspace on TechRepublic. You’ll be glad you did.
-
Produced by
ZDNet and






