Authors
Hideki Koike, Kazuhiro Ohno
Publication date
2004/10/29
Book
Proceedings of the 2004 ACM workshop on Visualization and data mining for computer security
Pages
143-147
Description
False detection is a major issue in deploying and maintaining Network-based Intrusion Detection Systems (NIDS). Traditionally, it is recommended to customize its signature database (DB) to reduce false detections. However, it requires quite deep knowledge and skills to appropriately customize the signature DB. Inappropriate customization causes the increase of false negatives as well as false positives. In this paper, we propose a visualization system of a NIDS log, named SnortView, which supports administrators in analyzing NIDS alerts much faster and much more easily. Instead of customizing the signature DB, we propose to utilize visualization to recognize not only each alert but also false detections. The system is based on a 2-D time diagram and alerts are shown as icons with different styles and colors. In addition, the system introduces some visualization techniques such as overlayed statistical …
Total citations
200320042005200620072008200920102011201220132014201520162017201820192020202120222023191911146171213111691112674233
Scholar articles
H Koike, K Ohno - Proceedings of the 2004 ACM workshop on …, 2004