Talk With an Expert

Intelligent Correlator for NIDS

Intelligent Correlator for NIDS (PDF, 2.34MB)Published: 19 Jun, 2003
Created by:
Marco Bove

In today NIDS the number of alerts may be huge and the delay in between an alert is generated and the system administrator analyzes it, can be too long and the situation can be changed, e.g. with dual boot Unix-Windows machines. Therefore we would like to give a low priority or to filter out not relevant alerts. We would like also to gather more information about the target of the attack at the time the attack has been performed. The goal of this work is the realization of a prototype of a system that reduces the number of false positives of a NIDS by triggering a real time collects for information upon alert reception.