loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
International conference on Networking and Services (ICNS'06)
Development of an Integrated Solution for Intrusion Detection: A Model Based on Data Correlation
Silicon Valley, California, USA
July 16-July 18
ISBN: 0-7695-2622-5
Joao Afonso, Pedro Nunes Institute, Coimbra, Portugal
Edmundo Monteiro, University of Coimbra, Coimbra, Portugal
Vitor Costa, Fisheries Inspection Department, Lisbon, Portugal
This work describes a solution for intrusion detection that presents an improved operational efficacy - both in terms of performance as well as volume of processed data - reducing at the same time the number of false negative and false positive results. For that purpose we correlate the data collected by the intrusion detection system with other data sources, such as events that are reported by interfacing equipment (edge devices) as well as other agents considered crucial for this purpose such as vulnerability detection solutions. As part of the proposed solution the data is collected in a Relational Data base System, to facilitate data correlation, as well as making it available through an easy to use web interface. Additionally, the system interacts with the network managers, in response to pre-defined triggers using a unified messaging platform that uses tools capable of processing E-Mails, Text Messages and also an instant messaging tool based of the XMPP protocol.
Citation:
Joao Afonso, Edmundo Monteiro, Vitor Costa, "Development of an Integrated Solution for Intrusion Detection: A Model Based on Data Correlation," icns, pp.37, International conference on Networking and Services (ICNS'06), 2006
Usage of this product signifies your acceptance of the Terms of Use.