Selective alerts for runtime protection of distributed systems

Michele Colajanni, D. Gozzi, Mirco Marchetti · WIT transactions on information and communication technologies · 2008

Network Intrusion Detection Systems (NIDS) are popular components for a fast detection of network attacks and intrusions, but their efficacy is limited by overwhelming amounts of false alarms that have to be manually managed by system administrators.In order to improve the efficacy of attack detection and reduce the amount of false positives, we propose a novel scheme for runtime alert management.It filters innocuous attacks by taking advantage of the correlation between the NIDS alerts and detailed information concerning the protected information systems, that is retrieved from heterogeneous and unstructured data sources.Thanks to the proposed scheme, an alert is sent to the system administrator only if an attack threatens some real vulnerability of the protected hosts.Otherwise, as it occurs in the large majority of the cases, the alert is stored for a subsequent offline analysis.The viability and efficacy of the proposed solution are demonstrated through an operative prototype that has been tested in networks subject to realistic attacks.

Read the paper · More papers on PaperTik