Scenario-Based Threat Detection and Analysis
Date Issued
2004
Date
2004
Author(s)
Hsiu, Pi-Cheng
DOI
en-US
Abstract
This thesis targets two essential issues in
intrusion detection system designs: the optimization of rule
selection and the attack discovery in attack analysis. A
scenario-based approach is proposed to correlate malicious packets
and to intelligently select intrusion detection rules to fire. We
propose algorithms for rule selection and attack scenario
identification. Potential threats and their relationship for a
gateway and web-server applications are explored as an example in
the study. The proposed algorithms are implemented over Snort, a
signature-based intrusion detection system, for which we have some
encouraging performance evaluation results.
Subjects
攻擊分析
入侵偵測系統
攻擊偵測
intrusion detection system
attack analysis
threat detection
Type
thesis
File(s)![Thumbnail Image]()
Loading...
Name
ntu-93-R91922004-1.pdf
Size
23.31 KB
Format
Adobe PDF
Checksum
(MD5):7649ce967e7c3419da138c6fa060aa11
