Paper Abstract and Keywords |
Presentation |
2016-07-14 13:25
Study on Classification Method of IDS Alerts Focusing on Relation of Detection Time Hiroaki Kuno, Hiroyuki Inaba (KIT) ISEC2016-19 SITE2016-13 ICSS2016-19 EMM2016-27 |
Abstract |
(in Japanese) |
(See Japanese page) |
(in English) |
IDS (Intrusion Detection System) is one of the countermeasures for illegal access to the network. Since IDS reports all of unauthorized or abnormal actions, management and analysis of the large amount of alert impose heavy burden on administrators. A method to combine related alerts into one is known to solve this problem. In this report, we consider the application of the method to IDS log analysis, and propose new method to generate sets of related alerts focused on detection time, IP address and signature of alerts. It is confirmed that the method can categorize IDS alerts to some specific groups. |
Keyword |
(in Japanese) |
(See Japanese page) |
(in English) |
IDS / alert / detection time / IP address / / / / |
Reference Info. |
IEICE Tech. Rep., vol. 116, no. 130, SITE2016-13, pp. 33-36, July 2016. |
Paper # |
SITE2016-13 |
Date of Issue |
2016-07-07 (ISEC, SITE, ICSS, EMM) |
ISSN |
Print edition: ISSN 0913-5685 Online edition: ISSN 2432-6380 |
Copyright and reproduction |
All rights are reserved and no part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information storage and retrieval system, without permission in writing from the publisher. Notwithstanding, instructors are permitted to photocopy isolated articles for noncommercial classroom use without fee. (License No.: 10GA0019/12GB0052/13GB0056/17GB0034/18GB0034) |
Download PDF |
ISEC2016-19 SITE2016-13 ICSS2016-19 EMM2016-27 |
Conference Information |
Committee |
EMM ISEC SITE ICSS IPSJ-CSEC IPSJ-SPT |
Conference Date |
2016-07-14 - 2016-07-15 |
Place (in Japanese) |
(See Japanese page) |
Place (in English) |
|
Topics (in Japanese) |
(See Japanese page) |
Topics (in English) |
security, etc |
Paper Information |
Registration To |
SITE |
Conference Code |
2016-07-EMM-ISEC-SITE-ICSS-CSEC-SPT |
Language |
Japanese |
Title (in Japanese) |
(See Japanese page) |
Sub Title (in Japanese) |
(See Japanese page) |
Title (in English) |
Study on Classification Method of IDS Alerts Focusing on Relation of Detection Time |
Sub Title (in English) |
|
Keyword(1) |
IDS |
Keyword(2) |
alert |
Keyword(3) |
detection time |
Keyword(4) |
IP address |
Keyword(5) |
|
Keyword(6) |
|
Keyword(7) |
|
Keyword(8) |
|
1st Author's Name |
Hiroaki Kuno |
1st Author's Affiliation |
Kyoto Institute of Technology (KIT) |
2nd Author's Name |
Hiroyuki Inaba |
2nd Author's Affiliation |
Kyoto Institute of Technology (KIT) |
3rd Author's Name |
|
3rd Author's Affiliation |
() |
4th Author's Name |
|
4th Author's Affiliation |
() |
5th Author's Name |
|
5th Author's Affiliation |
() |
6th Author's Name |
|
6th Author's Affiliation |
() |
7th Author's Name |
|
7th Author's Affiliation |
() |
8th Author's Name |
|
8th Author's Affiliation |
() |
9th Author's Name |
|
9th Author's Affiliation |
() |
10th Author's Name |
|
10th Author's Affiliation |
() |
11th Author's Name |
|
11th Author's Affiliation |
() |
12th Author's Name |
|
12th Author's Affiliation |
() |
13th Author's Name |
|
13th Author's Affiliation |
() |
14th Author's Name |
|
14th Author's Affiliation |
() |
15th Author's Name |
|
15th Author's Affiliation |
() |
16th Author's Name |
|
16th Author's Affiliation |
() |
17th Author's Name |
|
17th Author's Affiliation |
() |
18th Author's Name |
|
18th Author's Affiliation |
() |
19th Author's Name |
|
19th Author's Affiliation |
() |
20th Author's Name |
|
20th Author's Affiliation |
() |
Speaker |
Author-1 |
Date Time |
2016-07-14 13:25:00 |
Presentation Time |
25 minutes |
Registration for |
SITE |
Paper # |
ISEC2016-19, SITE2016-13, ICSS2016-19, EMM2016-27 |
Volume (vol) |
vol.116 |
Number (no) |
no.129(ISEC), no.130(SITE), no.131(ICSS), no.132(EMM) |
Page |
pp.33-36 |
#Pages |
4 |
Date of Issue |
2016-07-07 (ISEC, SITE, ICSS, EMM) |
|