Suchen und Finden

Titel

Autor/Verlag

Inhaltsverzeichnis

Nur eBooks für mein Endgerät anzeigen:

 

Newsletter

Intrusion Detection and Correlation

Intrusion Detection and Correlation

von: Christopher Kruegel, Fredrik Valeur, Giovanni Vigna

Kluwer Academic Publishers, 2005

ISBN: 9780387233994, 123 Seiten

Format: PDF, OL

Mac OSX,Windows PC Apple iPad, Android Tablet PC's Online-Lesen für: Linux,Mac OSX,Windows PC

Preis: 96,25 EUR

  • Kaiserkult in Kleinasien - Die Entwicklung der kultisch-religiösen Kaiserverehrung in der römischen Provinz Asia von Augustus bis Antoninus Pius
    Wenn die Mondblumen blühen - Roman
    Altern wie ein Gentleman - Zwischen Müßiggang und Engagement
    Der Mann, der durch das Jahrhundert fiel - Roman
    Alles auf eine Karte - Roman
    iPad-Programmierung
    Lux Domini - Thriller
    Das Twitter-Buch
  • Wo lassen Sie denken? - Warum der Glaube an die Wissenschaft uns dumm macht
    Das Facebook Marketing-Buch
    Glückstreffer - Roman
    Vintage your life! - Besser leben, weniger ausgeben zwischen Küche und Kleiderschrank
    Gefährtin der Finsternis - Roman
    Swimmingpool - Roman
    Behemoth - Im Labyrinth der Macht
    Light Against Darkness - Dualism in Ancient Mediterranean Religion and the Contemporary World
 

Mehr zum Inhalt

Intrusion Detection and Correlation


 

Contents

6

List of Figures

9

List of Tables

10

Preface

11

1 INTRODUCTION

13

1. Motivating Scenario

15

2. Alert Correlation

18

3. Organization

19

2 COMPUTER SECURITY AND INTRUSION DETECTION

20

1. Security Attacks and Security Properties

20

2. Security Mechanisms

22

2.1 Attack Prevention

22

2.2 Attack Avoidance

23

2.3 Attack Detection

28

3. Intrusion Detection

28

3.1 Architecture

30

3.2 Taxonomy

31

3.3 Detection Method

32

3.4 Type of Response

36

3.5 Audit Source Location

36

3.6 Usage Frequency

39

3.7 IDS Cooperation and Alert Correlation

39

3 ALERT CORRELATION

40

4 ALERT CORRELATION ALERT COLLECTION

45

1. Alert Normalization

46

2. Alert Preprocessing

47

2.1 Determining the Alert Time

48

2.2 Determining the Alert’s Source and Target

52

2.3 Determining the Attack’s Name

52

5 ALERT AGGREGATION AND VERIFICATION

53

1. Alert Fusion

53

2. Alert Verification

55

2.1 Passive Approach

58

2.2 Active Approach

58

3. Attack Thread Reconstruction

62

4. Attack Session Reconstruction

63

5. Attack Focus Recognition

66

6 HIGH-LEVEL ALERT STRUCTURES

68

1. Multistep Correlation

68

2. Impact Analysis

72

3. Alert Prioritizing

74

4. Alert Sanitization

75

7 LARGE-SCALE CORRELATION

80

1. Pattern Specification

86

1.1 Definitions

86

1.2 Attack Specification Language

87

1.3 Language Grammar

88

2. Pattern Detection

89

2.1 Basic Data Structures

89

2.2 Constraints

91

2.3 Detection Process

92

2.4 Implementation Issues

99

8 EVALUATION

102

1. Evaluation of Traditional ID Sensors

102

1.1 Evaluation Efforts

103

1.2 Problems

104

2. Evaluation of Alert Correlators

104

2.1 Evaluation Efforts

105

2.2 Problems

107

2.3 Correlation Evaluation Truth Files

108

2.4 Factors Affecting the Alert Reduction Rate

109

9 OPEN ISSUES

111

1. Intrusion Detection

111

2. Alert Correlation

114

10 CONCLUSIONS

116

References

118

Index

123