Hide metadata

dc.date.accessioned2013-05-09T10:22:57Z
dc.date.available2013-05-09T10:22:57Z
dc.date.issued2012en_US
dc.date.submitted2012-05-24en_US
dc.identifier.citationHaukeli, Jostein. False positive reduction through IDS network awareness. Masteroppgave, University of Oslo, 2012en_US
dc.identifier.urihttp://hdl.handle.net/10852/34902
dc.description.abstractThe common intrusion detection system is unable to determine the relevance of the alerts it generates because it lacks network and context awareness. A prototype was developed with the purpose of reducing the amount of false positives found in these systems. The prototype has the ability to determine the relevance of each alert by investigating the alert’s vulnerability information and the target’s host information. Challenges with passive fingerprinting of hosts behind Network Address Translation and in dynamic networks were also discussed and solved. Testing on real network traffic indicated that the prototypewas successful in correctly categorizing a variety of alerts by assigning scores to each alert. This way the alerts can be ordered by their likeliness of being true positives, and the number of alerts that the system administrator has to investigate is reduced to a manageable size.eng
dc.language.isoengen_US
dc.titleFalse positive reduction through IDS network awarenessen_US
dc.typeMaster thesisen_US
dc.date.updated2013-05-06en_US
dc.creator.authorHaukeli, Josteinen_US
dc.subject.nsiVDP::420en_US
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:dissertation&rft.au=Haukeli, Jostein&rft.title=False positive reduction through IDS network awareness&rft.inst=University of Oslo&rft.date=2012&rft.degree=Masteroppgaveen_US
dc.identifier.urnURN:NBN:no-33643en_US
dc.type.documentMasteroppgaveen_US
dc.identifier.duo164866en_US
dc.contributor.supervisorHårek Haugeruden_US
dc.identifier.bibsys131543733en_US
dc.identifier.fulltextFulltext https://www.duo.uio.no/bitstream/handle/10852/34902/1/jostein.pdf


Files in this item

Appears in the following Collection

Hide metadata