![buchspektrum Internet-Buchhandlung](../buchspektrumlogo.gif) Neuerscheinungen 2012Stand: 2020-01-07 |
Schnellsuche
ISBN/Stichwort/Autor
|
Herderstraße 10 10625 Berlin Tel.: 030 315 714 16 Fax 030 315 714 14 info@buchspektrum.de |
![](https://multimedia.knv.de/cover/33/93/75/3393757600001n.jpg)
Dominic Windisch
Automating Human Workflow in IDS Analysis
Simulation of Human Activity out of Log Files
Aufl. 2012. 96 S. 220 mm
Verlag/Jahr: AV AKADEMIKERVERLAG 2012
ISBN: 3-639-43127-8 (3639431278) / 3-8364-5459-9 (3836454599)
Neue ISBN: 978-3-639-43127-8 (9783639431278) / 978-3-8364-5459-9 (9783836454599)
Preis und Lieferzeit: Bitte klicken
Revision with unchanged content. Nowadays Intrusion Detection Systems (IDS) are still relying on human analysts, fulfilling the task of attack detection. The alarm overload produced by said systems requires a relief of the analyst´s daily workload. After an introduction to network security, the book presents an approach based on finite state machines (FSM), showing that human analysis behavior can be modeled directly from IDS log data. The specific alarm data alone revealed lacking information needed for the chosen Text Classification approach to create an operational decision model for the FSM. Further research is necessary. Rationales and suggestions to solve the problems are discussed. This work was written as Diploma Thesis at the Department of Informatics, University of Zurich in collaboration with Swisscom Innovations Inc, Bern, where this is also a spearhead of ongoing and future research in the area of traffic to protocol state machine reverse engineering.
Born and grown up in Central Switzerland, Dominic Windisch attended the first part of the Computer Science Engineer study program at ETH Zurich and changed to the Department of Informatics, University of Zurich for Information Management studies.