A Bayesian Classification on Asset Vulnerability for Real Time Reduction of False Positives in Ids

  • Jacob Victor G
N/ACitations
Citations of this article
7Readers
Mendeley users who have this article in their library.

Abstract

IT assets connected on internetwill encounter alien protocols and few parameters of protocol process are exposed as vulnerabilities. Intrusion Detection Systems (IDS) are installed to alerton suspicious traffic or activity. IDS issuesfalse positives alerts, if any behavior construe for partial attack pattern or the IDS lacks environment knowledge. Continuous monitoring of alerts to evolve whether, an alert is false positive or not is a major concern. In this paper we present design of an external module to IDS,to identify false positive alertsbased on anomaly based adaptive learning model. The novel feature of this design is that the system updates behavior profile of assets and environment with adaptive learning process.A mixture model is used for behavior modeling from reference data. The design of the detection and learning process are based on normal behavior and of environment. The anomaly alert identification algorithm isbuiltonSparse Markov Transducers (SMT) based probability.The total process is presented using real-time data. The Experimental results are validated and presentedwith reference to lab environment.

Cite

CITATION STYLE

APA

Jacob Victor, G. (2012). A Bayesian Classification on Asset Vulnerability for Real Time Reduction of False Positives in Ids. International Journal of Network Security & Its Applications, 4(2), 63–73. https://doi.org/10.5121/ijnsa.2012.4205

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free