Loading...
Please wait, while we are loading the content...
Similar Documents
An Incident Response Support System
| Content Provider | CiteSeerX |
|---|---|
| Author | Capuzzi, Gianluca Cardinale, Egidio Pietro, Ivan Di Spalazzi, Luca |
| Abstract | Computer and network security can be improved by three kinds of tools: tools for intrusion prevention, tools for intrusion detection, and tools for incident response. Many systems have been proposed and developed for the first two kinds of tools. Concerning the third, as far as we know, the response plan is still left to the security manager: no automatic tools have been developed. Indeed, even if there exist forensic analysis, data recovery, and system upgrading tools, we do not yet have a comprehensive tool which includes log correlation, attack classification, and response plan generation. Our work deals with a Case-Based Reasoning system (called IRSS) that classifies attacks, looks in a case base for past attacks similar to the current one (according to given similarity metrics), and reuses the past response plans (adapted to the current attack) in order to restore normal conditions and improve network security. This paper provides an overview of the system and primarly focuses on the incident retrieval (attack classification) phase. Key words: IDS, Network Security, Attack Recognition. |
| File Format | |
| Access Restriction | Open |
| Subject Keyword | Network Security Incident Response Support System Attack Classification Comprehensive Tool Past Response Plan Case Base Attack Recognition Incident Response Current One Many System Intrusion Detection Security Manager Work Deal Past Attack Forensic Analysis Log Correlation Case-based Reasoning System Normal Condition Response Plan Primarly Focus Intrusion Prevention System Upgrading Tool Response Plan Generation Incident Retrieval Current Attack Similarity Metric Data Recovery Automatic Tool |
| Content Type | Text |
| Resource Type | Article |