Abstract
Intrusion Detection Systems (IDS) are one of the most important tools in security field. The main aim of an IDS is to gather and analyze events from networks and hosts to identify signs of suspicious traffic. Having detected such signs, they generate alerts to report them. IDSs are known to generate a large number of false alerts, especially false alerts during the detection. Analyzing the alerts manually by security administrator need more time and makes it extremely difficult to correctly identify alerts related to attacks (true positives). In this paper, we introduce an approach to Intrusion Risk Assessment. The objective is to determine the impact of certain events on the security status of a network. In this approach, we evaluate the risk as a composition of certain parameters of alerts. Then we tightly integrate the Risk Assessment model with an existing framework, and we apply the results of the risk assessment to prioritize the alerts produced by the IDS.
Author supplied keywords
Cite
CITATION STYLE
Chakir, E. M., Moughit, M., & Khamlichi, Y. I. (2018). A real-time risk assessment model for intrusion detection systems using pattern matching. In Advances in Intelligent Systems and Computing (Vol. 640, pp. 229–237). Springer Verlag. https://doi.org/10.1007/978-3-319-64719-7_20
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.