Pushing the Limits in Event Normalisation to Improve Attack Detection in IDS/SIEM Systems

被引:8
作者
Azodi, Amir [1 ]
Jaeger, David [1 ]
Cheng, Feng [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, HPI, D-14482 Potsdam, Germany
来源
2013 INTERNATIONAL CONFERENCE ON ADVANCED CLOUD AND BIG DATA (CBD) | 2013年
关键词
D O I
10.1109/CBD.2013.27
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The current state of affairs regarding the way events are logged by IT systems is the source of many problems for the developers of Intrusion Detection Systems (IDS) and Security Information and Event Management (SIEM) systems. These problems stand in the way of the development of more accurate security solutions that draw their results from the data included within the logs they process. This is mainly caused by a lack of standards that can encapsulate all events in a coherent way. As a result, correlating between logs produced by different systems that use different log formats has been difficult and infeasible in many cases. In order to solve the challenges faced by Correlation Based Intrusion Detection Systems, we provide a platform for normalising events(1) into a unified super event loosely based on the Common Event Expression standard (CEE)[1] developed by the Mitre corporation[2]. We show how our solution is able to normalise seemingly unrelated events into a unified format. Additionally, we demonstrate queries that can detect attacks on collections of normalised logs from different sources.
引用
收藏
页码:69 / 76
页数:8
相关论文
共 28 条
[1]  
Allman E., 2002, SENDMAIL INSTALLATIO
[2]  
Apache, COMM BEANUTILS
[3]  
ArcSight H.-P., 2009, COMM EV FORM
[4]  
Avourdiadis N., 2005, P 4 EUR C INF WARF S, P9
[5]  
Avourdiadis N., 2006, P C COMP NETW DEF, P283
[6]  
Barnum S., 2012, CYBOX LANGU IN PRESS
[7]  
Board J. C. P., 2009, JSR 317 JAVA PERSIST
[8]  
Chuvakin A., 2008, COMMON EVENT EXPRESS
[9]  
Chuvakin A., 2005, SCAN MONTH CHALLENGG
[10]  
Cisco Systems Sourcefire Inc. The Snort Project, 2001, SNORT US MAN