download0 view909
twitter facebook

공공누리This item is licensed Korea Open Government License

dc.contributor.author
최상수
dc.contributor.author
박학수
dc.date.accessioned
2019-08-28T07:41:17Z
dc.date.available
2019-08-28T07:41:17Z
dc.date.issued
2013-12-31
dc.identifier.issn
1935-0090
dc.identifier.uri
https://repository.kisti.re.kr/handle/10580/14131
dc.description.abstract
Most organizations deploy and operate intrusion detection systems (IDSs) in order to cope with cyber attacks. However, in many cases, it is very difficult to not only analyze IDS alerts in realtime, but also identify real cyber attacks with a high detection accuracy because IDSs record the tremendous amount of alerts and most of them are false positives. Many approaches have been proposed to solve this issue, but there is a limitation in that they have focused on dealing with only IDS alerts. Therefore, in this paper, we propose a fusion framework of IDS alerts and darknet traffic, which is aiming at improving the effectiveness of the incident monitoring and response process. The experimental results show that the proposed framework could detect real cyber attacks that were not detected by IDSs and to identify more dangerous IDS alerts related to real cyber attacks.
dc.language
eng
dc.relation.ispartofseries
Applied mathematics & information sciences : an international journal
dc.title
A Fusion Framework of IDS Alerts and Darknet Traffic for Effective Incident Monitoring and Response
dc.subject.keyword
IDS Alerts
dc.subject.keyword
Darknet Traffic
dc.subject.keyword
Fusion Framework
dc.subject.keyword
Incident Monitoring and Response
Appears in Collections:
7. KISTI 연구성과 > 학술지 발표논문
Files in This Item:
There are no files associated with this item.

Browse