Automatic rule generation based on genetic programming for event correlation

17Citations
Citations of this article
27Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The widespread adoption of autonomous intrusion detection technology is overwhelming current frameworks for network security management. Modern intrusion detection systems (IDSs) and intelligent agents are the most mentioned in literature and news, although other risks such as broad attacks (e.g. very widely spread in a distributed fashion like botnets), and their consequences on incident response management cannot be overlooked. Event correlation becomes then essential. Basically, security event correlation pulls together detection, prevention and reaction tasks by means of consolidating huge amounts of event data. Providing adaptation to unknown distributed attacks is a major requirement as well as their automatic identification. This positioning paper poses an optimization challenge in the design of such correlation engine and a number of directions for research. We present a novel approach for automatic generation of security event correlation rules based on Genetic Programming which has been already used at sensor level. © Springer-Verlag Berlin Heidelberg 2009.

Cite

CITATION STYLE

APA

Suarez-Tangil, G., Palomar, E., De Fuentes, J. M., Blasco, J., & Ribagorda, A. (2009). Automatic rule generation based on genetic programming for event correlation. In Advances in Intelligent and Soft Computing (Vol. 63 AISC, pp. 127–134). https://doi.org/10.1007/978-3-642-04091-7_16

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free