• Title/Summary/Keyword: 오경

Search Result 2,481, Processing Time 0.042 seconds

False Positive Reduction for IDS using Decision Tree (결정트리를 이용한 IDS의 False Positive 감소기법)

  • Jeong, Kyeong-Ja
    • Proceedings of the KAIS Fall Conference
    • /
    • 2010.05a
    • /
    • pp.455-458
    • /
    • 2010
  • 침입탐지시스템은 공격이라고 판단되면 경보를 발생하여 보안 관리자에게 알려주거나 자체적으로 대응을 하게 된다. 그러나 이러한 경보들 중에 오경보가 많이 포함되어 있어 침입탐지시스템의 성능을 저하시킬 뿐 아니라 대량의 경보자체가 보안메커니즘에 방해가 되고 있다. 특히 오경보중 False Positive가 전체 오경보의 대부분을 차지하고 있다. 즉, False Positive는 정상 행위를 침입행위로 오인하여 판단하는 것을 의미한다. 경보들 중 이러한 오경보들은 네트워크 전반에 걸친 보안 서비스의 질을 하락시키는 원인이 된다. 따라서 침입탐지시스템의 성능향상을 위해서는 이러한 오경보 문제가 반드시 해결되어야 한다. 본 논문에서는 침입탐지시스템의 오경보를 감소시키는 결정트리 기반 오경보 분류모델을 제안하였다. 결정트리 기반 오경보 분류 모델은 침입탐지시스템의 오경보율을 감소시키고 침입탐지율을 향상시키는 역할을 수행한다는 것을 확인할 수 있었다.

  • PDF

A Study on the False Alarm Management of Alarm Monitoring Service (기계경비의 오경보 관리방안)

  • Chung, Tae-Hwang
    • Journal of the Society of Disaster Information
    • /
    • v.8 no.1
    • /
    • pp.93-99
    • /
    • 2012
  • This study is to present false alarm management of alarm monitoring service, by literature analysis and interview with the persons in charge of service of alarm monitoring service companies. To reduce false alarm by customer's mistake, development of educational tool that could provide practical effect is needed. Also institutional consent to charge a specific sum of money could be considered for unnecessary dispatch that occurred by customer's mistake. To improve the false alarm by defect of equipments and installation of electronic security system, standardization of technical regulation and system installation is necessary. And to improve the performance of passive infrared sensor that cause most false alarm, the development of new type of sensor is required. It could be considered that guideline on educational contents and term definition about false alarm could be come under the security regulation.

Classification of False Alarms based on the Decision Tree for Improving the Performance of Intrusion Detection Systems (침입탐지시스템의 성능향상을 위한 결정트리 기반 오경보 분류)

  • Shin, Moon-Sun;Ryu, Keun-Ho
    • Journal of KIISE:Databases
    • /
    • v.34 no.6
    • /
    • pp.473-482
    • /
    • 2007
  • Network-based IDS(Intrusion Detection System) gathers network packet data and analyzes them into attack or normal. They raise alarm when possible intrusion happens. But they often output a large amount of low-level of incomplete alert information. Consequently, a large amount of incomplete alert information that can be unmanageable and also be mixed with false alerts can prevent intrusion response systems and security administrator from adequately understanding and analyzing the state of network security, and initiating appropriate response in a timely fashion. So it is important for the security administrator to reduce the redundancy of alerts, integrate and correlate security alerts, construct attack scenarios and present high-level aggregated information. False alarm rate is the ratio between the number of normal connections that are incorrectly misclassified as attacks and the total number of normal connections. In this paper we propose a false alarm classification model to reduce the false alarm rate using classification analysis of data mining techniques. The proposed model can classify the alarms from the intrusion detection systems into false alert or true attack. Our approach is useful to reduce false alerts and to improve the detection rate of network-based intrusion detection systems.

Evaluation and Challenges of the 'Verified Report System' to reduce False Alarm (오경보 감소를 위한 '선별신고제도'의 평가와 과제)

  • Lee, Sanghun
    • Convergence Security Journal
    • /
    • v.15 no.1
    • /
    • pp.27-36
    • /
    • 2015
  • A discussion on false alarm is a series of problems about a waste of police resources. The the false alarm primarily increase machine the cost of security firm but ultimately increase the costs of national and social management. Verified Report System has been in operation since July 1, 2013, We could analyze the actual operation of 112 report on false alarm rate was 82.4% before this system launched, but after implementation of the Verified Report System, this rate level downs below 69.7% records. So 12.7% is declined at the rate of false alarm. However, the actual alarm rate of Electronic Security itself is just only 0.3 % in the total number of cases responding in contrast to Police is considerable. It is more urgent to evolve the Verified Report System, so penalty system against the false alarm, Police registration system of sensors, and strengthening of the task of the company for installation and management of detection equipment are urgently needed.