Talk With an Expert

Efficiently Deducing IDS False Positives Using System Profiling

Efficiently Deducing IDS False Positives Using System Profiling (PDF, 2.80MB)Published: 09 Nov, 2009
Created by:
Michael Karwaski

It is all too often modern day security analysts are plagued with security events that are irrelevant to a targeted host. Current applications and technologies attempt to eliminate these events by means of manually disabling and altering IPS/IDS rulesets. While this technology works, it does not provide an automated process for distinguishing the higher priority events from the low/irrelevant security risks. This paper is aimed at describing how to create a simple, static inventory database, then comparing security alerts to see if they relate to the host in question. This will allow for greater visibility into which alerts are actually relevant to the end users network.