Wir verwenden Cookies und Analyse-Tools, um die Nutzerfreundlichkeit der Internet-Seite zu verbessern und für Marketingzwecke. Wenn Sie fortfahren, diese Seite zu verwenden, nehmen wir an, dass Sie damit einverstanden sind. Zur Datenschutzerklärung.
Correlation and Aggregation of Security Alerts in Networks
Details
The tremendous increase in usage and complexity of modern communication and network systems connected to the Internet, places demands upon security management to protect organisations sensitive data and resources from malicious intrusion. A methodology for analysing alerts using a proposed framework for alert correlation, has been presented to provide the security operator with a global view of the security perspective. Missed alerts are recovered implicitly using a contextual technique to detect multi-stage attack scenarios. This is based on the assumption that the most serious intrusions consist of relevant steps that temporally ordered. The pre- and post- condition approach is used to identify the logical relations among low level alerts. The alerts are aggregated, verified using vulnerability modelling, and correlated to construct multi-stage attacks.A number of algorithms have been proposed in this book to support the functionality of our framework including: alert correlation, alert aggregation and graph reduction. These algorithms have been implemented in a tool called Multi-stage Attack Recognition System (MARS) consisting of a collection of integrated components.
Autorentext
Faeiz Alserhani received a BSc in Computer Engineering from King Saud University(Riyadh-Saudi Arabia). He subsequently completed an MSc in Networking from University of Essex (Colchester-UK). He received his PhD in Network Security from (University of Bradford - UK) in 2011. His interests include network security and Intrusion detection systems
Weitere Informationen
- Allgemeine Informationen
- GTIN 09783847345084
- Sprache Englisch
- Auflage Aufl.
- Größe H220mm x B150mm x T15mm
- Jahr 2012
- EAN 9783847345084
- Format Kartonierter Einband (Kt)
- ISBN 978-3-8473-4508-4
- Titel Correlation and Aggregation of Security Alerts in Networks
- Autor Faeiz Alserhani , Irfan Awan , Monis Akhlaq
- Untertitel A reasoning correlation and aggregation approach to detect multi-stage attack scenarios using elementary alerts generate
- Gewicht 398g
- Herausgeber LAP Lambert Academic Publishing
- Anzahl Seiten 256
- Genre Informatik