DocumentCode :
2626929
Title :
Guessing strategy for improving intrusion detections
Author :
Nehinbe, Joshua Ojo
Author_Institution :
Sch. of Comput. Sci. & Electron. Eng. Syst., Univ. of Essex, Colchester, UK
fYear :
2010
fDate :
8-9 Sept. 2010
Firstpage :
1
Lastpage :
6
Abstract :
Intrusion detectors isolate intrusions based on allowable and disallowable activities. The disallowable policy enforcers will alert only on events that are known to be bad while the allowable policy enforcer will alert on events that deviate from those that have been classified as good. However, these trade-offs become difficult to balance in a recent time due to the complexity of computer attacks. Accordingly, intrusion detectors generate tons of alerts that may signify realistic and false attacks. Most often, failed attacks are erroneously predicted and processed while classification trees that should have given detail descriptions of each clusters of the attacks are poorly constructed. This is because the qualities of clustering schemes that are generated are not evaluated with an appropriate model. Consequently, attacks in progress are not forestalled despite alerts that intrusion detectors generate beforehand. Therefore, this paper presents category utility paradigm for showing a good way of using clustering algorithm to partition audit trails. Series of evaluations showed how to adopt guessing strategy to improve the efficacy of intrusion detections.
Keywords :
computer network security; pattern classification; pattern clustering; trees (mathematics); classification trees; clustering algorithm; computer attack; guessing strategy; intrusion detection; policy enforcers; utility paradigm; Algorithm design and analysis; Classification algorithms; Clustering algorithms; Detectors; Intrusion detection; Partitioning algorithms; Prediction algorithms; Overlapping cluster; failed attacks; intrusion detection system;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Science and Electronic Engineering Conference (CEEC), 2010 2nd
Conference_Location :
Colchester
Print_ISBN :
978-1-4244-9029-5
Type :
conf
DOI :
10.1109/CEEC.2010.5606488
Filename :
5606488
Link To Document :
بازگشت