FREE Registration is required
Overview:
This paper presents an architecture1 designed for alert verification (i.e., to reduce false positives) in network intrusion-detection systems. The technique in this paper is based on a systematic (and automatic) anomaly-based analysis of the system output, which provides useful context information regarding the network services. The false positives raised by the NIDS analyzing the incoming traffic (which can be either signature- or anomaly-based) are reduced by correlating them with the output anomalies. An architecture for TCP-based network services was designed which has a client/server architecture (such as HTTP).
(Is this item miscategorized? Does it need more tags? Let us know.)
| Format: | Size: | 270 KB | |
| Date: | Sep 2007 | ||
| Pages: | 12 |
People who downloaded this item also downloaded
Top results from Security Tools
White Papers, Webcasts, and Resources
- Orthopedic Center to Grow 30 Percent and Boost Productivity With Online Services MicrosoftRead how one healthcare provider dramatically lowered costs--saving over $35,000 annually on licensing fees alone--using Microsoft Online Services.
- Live Webcast: Get Control over SaaS Application Access TriCipherLearn to simplify and protect access to your company's data in Software-as-a-Service (SaaS) apps using identity and access management best practices.
- Adopting Server Virtualization for Business Continuity and Disaster Recovery CA XOsoftDiscover the advantages of server virtualization for building an IT infrastructure with robust business continuity and disaster recovery capabilities.
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- World-class technology. Priced for your world.
-
Click here to learn how EMC solutions for small and medium businesses provide proven technology that is easy to deploy and simple to manage.

- Learn more >>
Featured Training Courses
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
- Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report







