Title :
Applying multi-correlation for improving forecasting in cyber security
Author :
Pontes, Elvis ; Guelfi, A.E. ; Kofuji, S.T. ; Silva, A.A.A.
Author_Institution :
Lab. of Integrated Syst., Univ. of Sao Paulo (EPUSP), São Paulo, Brazil
Abstract :
Currently, defense of the cyber space is mostly based on detection and/or blocking of attacks (Intrusion Detection and Prevention System - IDPS). But, a significant improvement for IDPS is the employment of forecasting techniques in a Distributed Intrusion Forecasting System (DIFS), which enables the capability for predicting attacks. Notwithstanding, during our earlier works, one of the issues we have faced was the huge amount of alerts produced by IDPS, several of them were false positives. Checking the veracity of alerts through other sources (multi-correlation), e.g. logs taken from the operating system (OS), is a way of reducing the number of false alerts, and, therefore, improving data (historical series) to be used by the DIFS. The goal of this paper is to propose a two stage system which allows: (1) employment of an Event Analysis System (EAS) for making multi-correlation between alerts from an IDPS with the OS´ logs; and (2) applying forecasting techniques on data generated by the EAS. Tests applied on laboratory by the use of the two stage system allow concluding about the improvement of the historical series reliability, and the consequent improvement of the forecasts accuracy.
Keywords :
operating systems (computers); security of data; cyber security forecasting; cyber space; distributed intrusion forecasting system; event analysis system; historical series reliability; intrusion detection and prevention system; multicorrelation; operating system; Correlation; Forecasting; Internet; Logic gates; Prototypes; Security; Sensors; allert correlation; attacks prediction; false positives; intrusion forecasting;
Conference_Titel :
Digital Information Management (ICDIM), 2011 Sixth International Conference on
Conference_Location :
Melbourn, QLD
Print_ISBN :
978-1-4577-1538-9
DOI :
10.1109/ICDIM.2011.6093323