Analyzing Root Causes of Intrusion Detection False-Negatives: Methodology and Case Study

09/18/2019
by   Eric Ficke, et al.
0

Intrusion Detection Systems (IDSs) are a necessary cyber defense mechanism. Unfortunately, their capability has fallen behind that of attackers. This motivates us to improve our understanding of the root causes of their false-negatives. In this paper we make a first step towards the ultimate goal of drawing useful insights and principles that can guide the design of next-generation IDSs. Specifically, we propose a methodology for analyzing the root causes of IDS false-negatives and conduct a case study based on Snort and a real-world dataset of cyber attacks. The case study allows us to draw useful insights.

READ FULL TEXT
research
06/04/2018

Provenance-based Intrusion Detection: Opportunities and Challenges

Intrusion detection is an arms race; attackers evade intrusion detection...
research
07/13/2008

Intrusion Detection Using Cost-Sensitive Classification

Intrusion Detection is an invaluable part of computer networks defense. ...
research
02/24/2020

Cry Wolf: Toward an Experimentation Platform and Dataset for Human Factors in Cyber Security Analysis

Computer network defense is a partnership between automated systems and ...
research
06/27/2019

Multivariate Big Data Analysis for Intrusion Detection: 5 steps from the haystack to the needle

The research literature on cybersecurity incident detection & response i...
research
01/29/2020

Intrusion Detection using ASTDs

In this paper, we show the application of ASTDs to intrusion detection. ...
research
09/12/2019

Toward Proactive, Adaptive Defense: A Survey on Moving Target Defense

Reactive defense mechanisms, such as intrusion detection systems, have m...
research
08/18/2018

Runtime Analysis of Whole-System Provenance

Identifying the root cause and impact of a system intrusion remains a fo...

Please sign up or login with your details

Forgot password? Click here to reset