The methods of decreasing FP in Anomaly based Intrusion Prevent System by using of complex information about information system

Вантажиться...
Ескіз

Дата

2024

Науковий керівник

Назва журналу

Номер ISSN

Назва тому

Видавець

Igor Sikorsky Kyiv Polytechnic Institute

Анотація

The main aim of this work is to optimize the efficiency of intrusion detection using complex analysis of indicators in information system by reducing the number of false positives, as well as the development of a universal technique for such optimization.Using laboratory environment with installed SIEMs Wazuh and Splunk we test the proposed optimization methods and proposed newly methodic for decreasing rating false/positive for some intrusion detecting systems.

Опис

Ключові слова

False Positives Optimization, Intrusion Detection Systems (IDS), Anomalies Detection, Comprehensive Behavioral Analysis, Security Information And Event Management (SIEM), Signatureless Intrusion Detection Methods

Бібліографічний опис

Kudin, A. The methods of decreasing FP in Anomaly based Intrusion Prevent System by using of complex information about information system / Anton Kudin, Olga Grigorieva, Svitlana Nosok // Theoretical and Applied Cybersecurity: scientific journal. – 2024. – Vol. 6, No. 1. – P. 26-31. – Bibliogr.: 33 ref.

ORCID