Browse > Article
http://dx.doi.org/10.13089/JKIISC.2003.13.3.135

An Aggregate Detection of Event Correlation using Fuzzy Control  

김용민 (전남대학교 보안연구센터)
Abstract
An intrusion detection system shows different result over overall detection area according to its detection characteristics of inner detection algorithms or techniques. To expand detection areas, we requires an integrated detection which can be archived both by deploying a few detection systems which detect different detection areas and by combining their results. In addition to expand detection areas, we need to decrease the workload of security managers by false alarms and improve the correctness by minimizing false alerts which happen during the process of integration. In this paper, a method for aggregation detection use fuzzy inference to integrate a vague detection results which imply the characteristics of detection systems. Their analyzed detection characteristics are expressed as fuzzy membership functions and fuzzy rule bases which are applied through the process of fuzzy control. And, it integrate a vague decision results and minimize the number of false alerts by reflecting the characteristics of detection systems. Also it does minimize inference objects by applying thresholds decided through several experiments.
Keywords
IDS; Correlation; Aggregate Detection; Fuzzy control;
Citations & Related Records
Times Cited By KSCI : 1  (Citation Analysis)
연도 인용수 순위
1 Towards a Taxonomy of Intrusion Detection Systems and Attacks /
[ C,Christian;D.Mark(et al.) ] / Research Report RZ 3366, IBM Research
2 이종의 침입탐지센서 관련성을 이용한 통합탐지의 민감도 향상 기법 /
[ 김용민;김민수;김홍근;노봉남 ] / 정보보호학회논문지   과학기술학회마을
3 /
[ 이광형;오길록 ] / 퍼지이론 및 응용-1,2권
4 LAMBDA : A Language to Model a Database for detection of attacks /
[ F.Cuppens;R.Ortalo ] / Proc.of the 3rd International Workshop on the Recent Advances in Intresion Delection(RAID'2000)
5 EMERALD: Event Monitoring Enabling Responses To Anomalous Live Disturbances /
[ P.A.Porras;P.G.Neumann ] / Proc. of the 20th National Information Systems Security Conference
6 퍼지제어를 이용한 다중 탐지시스템의 통합탐지 방법 /
[ 김상찬;김용민;김민수;노봉남 ] / 정보과학회 가을 학술발표논문집(Ⅰ)
7 Probabilistic Alert Correlation /
[ A.Valdes;K.Skinner ] / 4th International Symposium on the Recent Advances in Intrusion Detection
8 Evolving Fuzzy Classifiers for Intrusion Detection /
[ J.Gomez;D.Dasgupta ] / Proc. of IEEE Workshop on Information Assurance
9 Alert Correlation in a Cooperative Intrusion Detection Framework /
[ F.Cuppens;A.Miege ] / IEEE Symposium on Security and Privacy
10 An Approach to Sensor Correlation /
[ A.Valdes;K.Skinner ] / 3rd International Workshop on the Recent Advances in Intrusion Detection
11 Fuzzy Preference Approach for Computer Network Attack Detection /
[ M.Manic;B.Wilamowski ] / International Joint Conference on Neural Networks(IJCNN'01)