Selecting appropriate ecounter-measures in an intrusion detection framework - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2004

Selecting appropriate ecounter-measures in an intrusion detection framework

Résumé

Since current computer infrastructures are increasingly vulnerable to malicious activities, intrusion detection is necessary but unfortunately not sufficient. We need to design effective response techniques to circumvent intrusions when they are detected. Our approach is based on a library that implements different types of counter-measures. The idea is to design a decision support tool to help the administrator to choose, in this library, the appropriate counter-measure when a given intrusion occurs. For this purpose, we formally define the notion of anti-correlation which is used to determine the counter-measures that are effective to stop the intrusion. Finally, we present a platform of intrusion detection, called DIAMS, that implements the response mechanisms presented in this paper.

Mots clés

Fichier non déposé

Dates et versions

hal-01923668 , version 1 (15-11-2018)

Identifiants

Citer

Frédéric Cuppens, Sylvain Gombault, Thierry Sans. Selecting appropriate ecounter-measures in an intrusion detection framework. ICSF 2004: 17th IEEE Computer security foundation workshop, Jun 2008, Pacific Grove - Californie, United States. ⟨10.1109/CSFW.2004.1310733⟩. ⟨hal-01923668⟩
20 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More