OSSEC IDS extension to improve log analysis and override false positive or negative detections

dc.contributor.authorTeixeira, Diogopor
dc.contributor.authorAssunção, Leonardopor
dc.contributor.authorPereira, Teresapor
dc.contributor.authorMalta, Silvestrepor
dc.contributor.authorPinto, Pedropor
dc.date.accessioned2024-03-20T19:09:25Z
dc.date.available2024-03-20T19:09:25Z
dc.date.issued2019
dc.description.abstractIntrusion Detection Systems (IDS) are used to prevent attacks by detecting potential harmful intrusion attempts. Currently, there are a set of available Open Source IDS with different characteristics. The Open Source Host-based Intrusion Detection System (OSSEC) supports multiple features and its implementation consists of Agents that collect and send event logs to a Manager that analyzes and tests them against specific rules. In the Manager, if certain events match a specific rule, predefined actions are triggered in the Agents such as to block or unblock a particular IP address. However, once an action is triggered, the systems administrator is not able to centrally check and obtain detailed information of the past event logs. In addition, OSSEC may assume false positive or negative detections and their triggered actions: previously harmless but blocked IP addresses by OSSEC have to be unblocked in order to reestablish normal operation or potential harmful IP addresses not previously blocked by OSSEC should be blocked in order to increase protection levels. These operations to override OSSEC actions must be manually performed in every Agent, thus requiring time and human resources. Both these limitations have a higher impact on large scale OSSEC deployments assuming tens or hundreds of Agents. This paper proposes an extension to OSSEC that improves the administrator analysis capability by maintaining, organizing and presenting Agent logs in a central point, and it allows for blocking or unblocking IP addresses in order to override actions triggered by false detections. The proposed extension aims to increase efficiency of time and human resources management, mainly considering large scale OSSEC deployments.por
dc.distributioninternationalpor
dc.identifier.citationTeixeira, D.; Assunção, L.; Pereira, T.; Malta, S.; Pinto, P. OSSEC IDS Extension to Improve Log Analysis and Override False Positive or Negative Detections. J. Sens. Actuator Netw. 2019, 8, 46. https://doi.org/10.3390/jsan8030046por
dc.identifier.doi10.3390/jsan8030046por
dc.identifier.eissn2224-2708
dc.identifier.urihttps://hdl.handle.net/1822/89777
dc.language.isoengpor
dc.peerreviewedyespor
dc.publisherMDPIpor
dc.relation.publisherversionhttps://www.mdpi.com/2224-2708/8/3/46por
dc.rightsopenAccesspor
dc.rights.urihttp://creativecommons.org/licenses/by/4.0/por
dc.subjectIDSpor
dc.subjectOSSECpor
dc.subjectcybersecuritypor
dc.subjectinformation securitypor
dc.subjectattack detectionpor
dc.subjectsecurity eventspor
dc.subjectintrusionspor
dc.subject.fosCiências Naturais::Ciências da Computação e da Informaçãopor
dc.subject.wosScience & Technologypor
dc.titleOSSEC IDS extension to improve log analysis and override false positive or negative detectionspor
dc.typearticlepor
dspace.entity.typePublicationen
oaire.citationIssue3por
oaire.citationVolume8por
oaire.versionVoRpor
sdum.journalJournal of Sensor and Actuator Networkspor

Ficheiros

Pacote original

A mostrar 1 - 1 de 1
A carregar...
Nome:
jsan-08-00046.pdf
Tamanho:
629.68 KB
Formato:
Adobe Portable Document Format
Descrição: