Affiliation:
1. East China Institute of Technology
Abstract
The research actuality of Intrusion Detection System(IDS) were analyzed, Due to the defects of IDS such as high positive rate of IDS and incapable of effective detection of dispersed coordinated attacks on the time and space, the ideas of the multi-source information fusion were introduced in the paper, a multi-level IDS reasoning framework and prototype system were presented. The prototype adds analysis engine to the existing IDS Sensor, We used Bayesian Network as a tool for multi-source information fusion, and we used goal-tree to analyze the attempts of coordinated attacks and quantify the security risk of system. Compared to the existing IDS, the prototype is more integrated and more capable in finding coordinated attacks with lower false positive rate.
Publisher
Trans Tech Publications, Ltd.
Reference6 articles.
1. Bedworth M, Brein J O. The Omnibus Model: A New Model of Data Fusion[M] . IEEE AES Systems Magazine, (2006).
2. Dasarathy B V. Fuzzy Evidential Reasoning Approach to Target Identity and State Fusion in Multi-Sensor Environments. Optical Engineering, 2007, 36(3): 669~683.
3. Talreja D, Linas J, Bowman C. A framework for performance evaluation of multi target tracking systems-partII: Analysis methods. New York: University at Bufalo, (2004).
4. White G B, Fisch E A, Pooch U.W. Cooperating security managers: peer- based intrusion detection system. IEEE Network. 1996. 10(1): 20~23.
5. Stephen Northcutt network intrusion detection: an analyst's handbook. New Riders Publishing, (1999).