A real-time risk assessment model for intrusion detection systems using pattern matching

2Citations
Citations of this article
6Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Intrusion Detection Systems (IDS) are one of the most important tools in security field. The main aim of an IDS is to gather and analyze events from networks and hosts to identify signs of suspicious traffic. Having detected such signs, they generate alerts to report them. IDSs are known to generate a large number of false alerts, especially false alerts during the detection. Analyzing the alerts manually by security administrator need more time and makes it extremely difficult to correctly identify alerts related to attacks (true positives). In this paper, we introduce an approach to Intrusion Risk Assessment. The objective is to determine the impact of certain events on the security status of a network. In this approach, we evaluate the risk as a composition of certain parameters of alerts. Then we tightly integrate the Risk Assessment model with an existing framework, and we apply the results of the risk assessment to prioritize the alerts produced by the IDS.

Cite

CITATION STYLE

APA

Chakir, E. M., Moughit, M., & Khamlichi, Y. I. (2018). A real-time risk assessment model for intrusion detection systems using pattern matching. In Advances in Intelligent Systems and Computing (Vol. 640, pp. 229–237). Springer Verlag. https://doi.org/10.1007/978-3-319-64719-7_20

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free