Results (
Thai) 1:
[Copy]Copied!
IDS for computer network is capable of detecting and alerting the systems administrator onpotential intrusion, providing guidance against any potential loss of integrity and confidentiality to theenterprise’s valuable intellectual assets. In this paper, the layered model for IDS and alert aggregationtechnique is used. In this layered IDS architecture, each layer assesses, filters, and/or aggregatesinformation produced by a lower layer. Thus, relevant information gets more and more condensed andcertain, and, therefore, also more valuable. Alert may originate from low-level IDS such as thosementioned above, from firewalls (FW), etc. Alerts that belong to one attack instance must be clusteredtogether and meta-alerts must be generated. The main goal is to improve performance by reducing theamount of alerts substantially without losing any important information which is necessary to identify ongoingattack instances
Being translated, please wait..