Skip to main navigation Skip to search Skip to main content

An attack-feedback-based approach for verifying the success of intrusion attempts

  • Zhi Hong Tian*
  • , Bin Li
  • , Hong Li Zhang
  • *Corresponding author for this work
  • Harbin Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

It is well-known that current Intrusion Detection Systems produce large numbers of false alerts. Those low quality alerts make it very hard for administrators to understand and take appropriate actions. To deal with false positive, in this paper, an attack-feedback-based approach is introduced to verify the success of attacks. This method processes each packet as soon as it is received. When a suspect packet is indicative of an attack on an existing network service, the effects of that packet on the host will be further tracked by following the causal dependencies. The experimental results have shown that the proposed technique is highly effective in reducing the alert volume and verifying the success of intrusion attempts.

Original languageEnglish
Title of host publication2006 International Conference on Computational Intelligence and Security, ICCIAS 2006
PublisherIEEE Computer Society
Pages629-632
Number of pages4
ISBN (Print)1424406056, 9781424406050
DOIs
StatePublished - 2006
Event2006 International Conference on Computational Intelligence and Security, ICCIAS 2006 - Guangzhou, China
Duration: 3 Oct 20066 Oct 2006

Publication series

Name2006 International Conference on Computational Intelligence and Security, ICCIAS 2006
Volume1

Conference

Conference2006 International Conference on Computational Intelligence and Security, ICCIAS 2006
Country/TerritoryChina
CityGuangzhou
Period3/10/066/10/06

Fingerprint

Dive into the research topics of 'An attack-feedback-based approach for verifying the success of intrusion attempts'. Together they form a unique fingerprint.

Cite this