Panacea: Automating Attack Classification for Anomaly-based Network Intrusion Detection Systems

D. Bolzoni, Sandro Etalle, Pieter H. Hartel

    Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

    891 Downloads (Pure)

    Abstract

    Anomaly-based intrusion detection systems are usually criticized because they lack a classication of attack, thus security teams have to manually inspect any raised alert to classify it. We present a new approach, Panacea, to automatically and systematically classify attacks detected by an anomaly-based network intrusion detection system.
    Original languageUndefined
    Title of host publicationRecent Advances in Intrusion Detection (RAID)
    EditorsE. Kirda, S. Jha, D. Balzarotti
    Place of PublicationHeidelberg
    PublisherSpringer
    Pages1-20
    Number of pages21
    ISBN (Print)978-3-642-04341-3
    DOIs
    Publication statusPublished - Sep 2009
    EventRecent Advances in Intrusion Detection -
    Duration: 1 Sep 20091 Sep 2009

    Publication series

    NameLecture Notes in Computer Science
    PublisherSpringer Verlag
    Volume5758

    Conference

    ConferenceRecent Advances in Intrusion Detection
    Period1/09/091/09/09

    Keywords

    • METIS-264059
    • IR-68138
    • SCS-Cybersecurity
    • attack classification
    • EWI-16130
    • anomaly-based intrusion detection systems

    Cite this