• DocumentCode
    2501205
  • Title

    Development of an Integrated Solution for Intrusion Detection: A Model Based on Data Correlation

  • Author

    Afonso, João ; Monteiro, Edmundo ; Costa, Vitor

  • Author_Institution
    Pedro Nunes Inst., Coimbra
  • fYear
    2006
  • fDate
    16-18 July 2006
  • Firstpage
    37
  • Lastpage
    37
  • Abstract
    This work describes a solution for intrusion detection that presents an improved operational efficacy - both in terms of performance as well as volume of processed data - reducing at the same time the number of false negative and false positive results. For that purpose we correlate the data collected by the intrusion detection system with other data sources, such as events that are reported by interfacing equipment (edge devices) as well as other agents considered crucial for this purpose such as vulnerability detection solutions. As part of the proposed solution the data is collected in a relational data base system, to facilitate data correlation, as well as making it available through an easy to use Web interface. Additionally, the system interacts with the network managers, in response to pre-defined triggers using a unified messaging platform that uses tools capable of processing e-mails, text messages and also an instant messaging tool based of the XMPP protocol
  • Keywords
    Internet; computer network management; data communication; electronic mail; electronic messaging; protocols; relational databases; security of data; telecommunication security; Web interface; XMPP protocol; data correlation; data sources; e-mails; instant messaging tool; intrusion detection; network managers; relational data base system; text messages; unified messaging platform; vulnerability detection solutions; Aquaculture; Computer network management; Computerized monitoring; Electronic mail; Event detection; Inspection; Intrusion detection; Network servers; Protocols; Remote monitoring;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networking and Services, 2006. ICNS '06. International conference on
  • Conference_Location
    Slicon Valley, CA
  • Print_ISBN
    0-7695-2622-5
  • Type

    conf

  • DOI
    10.1109/ICNS.2006.39
  • Filename
    1690508