buchspektrum Internet-Buchhandlung

Neuerscheinungen 2012

Stand: 2020-01-07
Schnellsuche
ISBN/Stichwort/Autor
Herderstraße 10
10625 Berlin
Tel.: 030 315 714 16
Fax 030 315 714 14
info@buchspektrum.de

Dominic Windisch

Automating Human Workflow in IDS Analysis


Simulation of Human Activity out of Log Files
Aufl. 2012. 96 S. 220 mm
Verlag/Jahr: AV AKADEMIKERVERLAG 2012
ISBN: 3-639-43127-8 (3639431278) / 3-8364-5459-9 (3836454599)
Neue ISBN: 978-3-639-43127-8 (9783639431278) / 978-3-8364-5459-9 (9783836454599)

Preis und Lieferzeit: Bitte klicken


Revision with unchanged content. Nowadays Intrusion Detection Systems (IDS) are still relying on human analysts, fulfilling the task of attack detection. The alarm overload produced by said systems requires a relief of the analyst´s daily workload. After an introduction to network security, the book presents an approach based on finite state machines (FSM), showing that human analysis behavior can be modeled directly from IDS log data. The specific alarm data alone revealed lacking information needed for the chosen Text Classification approach to create an operational decision model for the FSM. Further research is necessary. Rationales and suggestions to solve the problems are discussed. This work was written as Diploma Thesis at the Department of Informatics, University of Zurich in collaboration with Swisscom Innovations Inc, Bern, where this is also a spearhead of ongoing and future research in the area of traffic to protocol state machine reverse engineering.
Born and grown up in Central Switzerland, Dominic Windisch attended the first part of the Computer Science Engineer study program at ETH Zurich and changed to the Department of Informatics, University of Zurich for Information Management studies.