dc.contributorSantos, Osmar Marchi dos
dc.contributorhttp://lattes.cnpq.br/3867718775277531
dc.contributorMaziero, Carlos Alberto
dc.contributorhttp://lattes.cnpq.br/5659788852261811
dc.contributorLegg, Andrei Piccinini
dc.contributorhttp://lattes.cnpq.br/9873333807426188
dc.creatorCeolin Junior, Tarcisio
dc.date.accessioned2015-02-19
dc.date.available2015-02-19
dc.date.created2015-02-19
dc.date.issued2014-02-28
dc.identifierCEOLIN JUNIOR, Tarcisio. ALERT CORRELATION IN AN INTERNET EARLY WARNING SYSTEM. 2014. 66 f. Dissertação (Mestrado em Ciência da Computação) - Universidade Federal de Santa Maria, Santa Maria, 2014.
dc.identifierhttp://repositorio.ufsm.br/handle/1/5439
dc.description.abstractIntrusion Detection Systems (IDS) are designed to monitor the computer network infrastructure against possible attacks by generating security alerts. With the increase of components connected to computer networks, traditional IDS are not capable of effectively detecting malicious attacks. This occurs either by the distributed amount of data that traverses the network or the complexity of the attacks launched against the network. Therefore, the design of Internet Early Warning Systems (IEWS) enables the early detection of threats in the network, possibly avoiding eventual damages to the network resources. The IEWS works as a sink that collects alerts from different sources (for example, from different IDS), centralizing and correlating information in order to provide a holistic view of the network. This way, the current dissertation describes an IEWS architecture for correlating alerts from (geographically) spread out IDS using the Case-Based Reasoning (CBR) technique together with IP Georeferencing. The results obtained during experiments, which were executed over the implementation of the developed technique, showed the viability of the technique in reducing false-positives. This demonstrates the applicability of the proposal as the basis for developing advanced techniques inside the extended IEWS architecture.
dc.publisherUniversidade Federal de Santa Maria
dc.publisherBR
dc.publisherCiência da Computação
dc.publisherUFSM
dc.publisherPrograma de Pós-Graduação em Informática
dc.rightsAcesso Aberto
dc.subjectCorrelação de alertas
dc.subjectDetecção de intrusão
dc.subjectConsciência situacional
dc.subjectAlert correlation
dc.subjectIntrusion detection
dc.subjectInternet Early Warning Systems
dc.subjectSituational awareness
dc.titleCorrelação de alertas em um Internet Early Warning Systems
dc.typeDissertação


Este ítem pertenece a la siguiente institución