loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
19th Annual Computer Security Applications Conference (ACSAC '03)
Attack Signature Matching and Discovery in Systems Employing Heterogeneous IDS
Las Vegas, Nevada
December 08-December 12
ISBN: 0-7692-2041-3
Nathan Carey, Queensland University of Technology
George Mohay, Queensland University of Technology
Andrew Clark, Queensland University of Technology
Over the past decade, Intrusion Detection Systems (IDS) have improved steadily in the efficiency and effectiveness with which they detect intrusive activity. This is particularly true with signature-based IDS due to progress with intrusion analysis and intrusion signature specification. At the same time system complexity, overall numbers of bugs and security vulnerabilities have been on the increase. This has led to the recognition that in order to operate over the entire attack space, multiple heterogeneous IDS must be used, which need to interoperate with one another, and possibly also with other components of system security. This paper describes our research into developing algorithms for attack signature matching for detecting multi-stage attacks manifested by alerts from heterogeneous IDS. It describes also the testing and preliminary results of that research, and the administrator interface used to analyze the alerts produced by the tests and the results of signature matching.
Citation:
Nathan Carey, George Mohay, Andrew Clark, "Attack Signature Matching and Discovery in Systems Employing Heterogeneous IDS," acsac, pp.245, 19th Annual Computer Security Applications Conference (ACSAC '03), 2003
Usage of this product signifies your acceptance of the Terms of Use.