ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Jobs
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

Download now

Real-Time Multistage Attack Awareness Through Enhanced Intrusion Alert Clustering

Did you find this white paper useful?
1 out of 2 users found this white paper useful


Publisher University at Buffalo
Publisher Registration N/A
Topics Security Tools, Intrusion Detection Systems Date added 01 Dec 2007
Downloads 10 Format 142.9KB PDF

Correlation and fusion of intrusion alerts to provide effective Situation Awareness of cyber-attacks has become an active area of research. Snort is the most widely deployed intrusion detection sensor. For many networks and their system administrators, the alerts generated by Snort are the primary indicators of network misuse and attacker activity. However, the volume of the alerts generated in typical networks makes real-time attack scenario comprehension dif-cult. This paper present an attack-stage oriented classification of alerts using Snort as an example, and demonstrate that this effectively improves real-time Situation Awareness of multistage attacks. It also incorporate this scheme into a real-time attack detection framework and prototype presented by the authors in previous work and provide some results from testing against multistage attack scenarios.

Download now

Did you find this white paper useful?
1 out of 2 users found this white paper useful


  • Trackback
  • Clip Link

Related white papers

Balancing Security Against Productivity

What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending attacks or preventing them? When IDG Research Services queried...


Novell Zenworks Endpoint Security Management: Total Control from a Single Console

Still super gluing your USB ports shut? Unauthorized access to networks, lost or stolen laptops and other mobile hardware, and theft of proprietary information or intellectual property accounted for more...


Secure Desktop On-Demand Webcast

The desktop or endpoint is one of the most vulnerable parts of your environment. Threats are everywhere. You have users who love to experiment with device settings (only to wonder...


Stop Spam and Email-Borne Threats With Symantec's New Hosted Mail Security Solution

Organizations of all sizes are coping with threats to business productivity and security from spam, viruses and worms, and other email-borne content. To combat these attacks, Symantec provides industry-leading email...


Securing SMBs Against Spam and Virus Threats

This white paper from St. Bernard Software explains why spam and viruses are particularly tough to eliminate in small- and medium-sized businesses (SMBs) that can't dedicate IT staff to combating...


Streamline User Administration with Novell Nsure Identity Manager 2

This information-packed white paper provides an in-depth look at the capabilities that are built into Novell Nsure Identity Manager 2, which provides an identity management foundation for account provisioning, security,...


Reduce the Risk of Costly Data Breaches: Three Pillars of Data Protection

There are numerous regulations that govern the protection of private, personal and confidential data regardless of whether the data resides on a secure mainframe computer, desktop PC or mobile device...


White Paper

Featured White Paper

11 things to consider for File Virtualization

As organizations struggle to cope with the exponential growth of data, especially in the unstructured and decentralized file space, the urgency to gain better control, visibility and transparency of file data also grows.

Download Now

Other White Papers

Inter-site Ethernet: A guide to choosing your Ethernet service provider

The market for Ethernet is continuing to grow, as UK organisations appreciate the cost savings,...

Laying the foundations for evolving eGovernment: Why next generation Ethernet technology holds the key

The UK Government has committed to transform the public sector by making truly e-enabled...

See All White Papers