PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
July 8, 2004102 citations

Log correlation for intrusion detection: a proof of concept

View Full Paper
CACristina L. AbadJTJohn TaylorCSCigdem Sengul

Key Points

Key points are not available for this paper at this time.

Abstract

Intrusion detection is an important part of networked-systems security protection. Although commercial products exist, finding intrusions has proven to be a difficult task with limitations under current techniques. Therefore, improved techniques are needed. We argue the need for correlating data among different logs to improve intrusion detection systems accuracy. We show how different attacks are reflected in different logs and argue that some attacks are not evident when a single log is analyzed. We present experimental results using anomaly detection for the virus Yaha. Through the use of data mining tools (RIPPER) and correlation among logs we improve the effectiveness of an intrusion detection system while reducing false positives.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Abad et al. (2004) studied this question.

synapsesocial.com/papers/6a0f297628dd8f49a2bdbfb5https://doi.org/10.1109/csac.2003.1254330
Ask AI
Helpful
Bookmark
Share
View Full Paper