<link rel="stylesheet" href="styles.f3b1fba60ec7970c.css">

Correlação de eventos para detecção de intrusão: um experimento com open source security information management (OSSIM)

Carregando...
Imagem de Miniatura

Título da Revista

ISSN da Revista

Título de Volume

Editor

Universidade Federal do Rio de Janeiro

DOI

Resumo

Recent studies have shown that it is possible to identify abnormalities in networks of computers automatically using techniques of learning and data mining. To see how the use of these techniques helps in the identification of abnormalities was chosen Open Source Security Information Management (OSSIM) tool for analysis. For this analysis, an experiment was set up to allow verification of the installation and configuration of the tool and the techniques of data mining for correlation of events from a computer network. The results show the feasibility of using these techniques for the correlation and analysis of events in automatic mode on a computer network. It was also difficult to identify the tool`s installation and configuration and the impact on the events correlation when the number of events was high.

Descrição

Citação

Avaliação

Revisão

Suplementado Por

Referenciado Por

Direitos e licensiamento

Acesso Aberto