Alerts Analysis and Visualization in Network-based Intrusion Detection Systems
- University of Tennessee
The alerts produced by network-based intrusion detection systems, e.g. Snort, can be difficult for network administrators to efficiently review and respond to due to the enormous number of alerts generated in a short time frame. This work describes how the visualization of raw IDS alert data assists network administrators in understanding the current state of a network and quickens the process of reviewing and responding to intrusion attempts. The project presented in this work consists of three primary components. The first component provides a visual mapping of the network topology that allows the end-user to easily browse clustered alerts. The second component is based on the flocking behavior of birds such that birds tend to follow other birds with similar behaviors. This component allows the end-user to see the clustering process and provides an efficient means for reviewing alert data. The third component discovers and visualizes patterns of multistage attacks by profiling the attacker s behaviors.
- Research Organization:
- Oak Ridge National Lab. (ORNL), Oak Ridge, TN (United States)
- Sponsoring Organization:
- Work for Others (WFO)
- DOE Contract Number:
- DE-AC05-00OR22725
- OSTI ID:
- 986830
- Resource Relation:
- Conference: The Second IEEE International Conference on Information Privacy, Security, Risk and Trust (PASSAT2010),, Minneapolis, MN, USA, 20100820, 20100822
- Country of Publication:
- United States
- Language:
- English
Similar Records
Multi stage attack Detection system for Network Administrators using Data Mining
Security Evaluation of Two Intrusion Detection Systems in Smart Grid SCADA Environment