Loading [MathJax]/extensions/MathMenu.js
Detecting Successful Attacks from IDS Alerts Based On Emulation of Remote Shellcodes | IEEE Conference Publication | IEEE Xplore

Detecting Successful Attacks from IDS Alerts Based On Emulation of Remote Shellcodes


Abstract:

Server administrators and security operation center analysts receive alerts from an intrusion detection system and check whether attacks have succeeded. However, it is di...Show More

Abstract:

Server administrators and security operation center analysts receive alerts from an intrusion detection system and check whether attacks have succeeded. However, it is difficult to handle them quickly because a tremendous number of alerts is generated in a short period of time. We propose a method to identify important alerts that lead to security incidents automatically. The key idea is to determine the success or failure of an attack based on traffic logs and the network behaviors observed during shellcode emulation. We evaluated the proposed method in terms of accuracy and performance and found that it can handle more than 60% of remote shellcodes and cope with practical attack cases.
Date of Conference: 15-19 July 2019
Date Added to IEEE Xplore: 09 July 2019
Print ISBN:978-1-7281-2607-4
Print on Demand(PoD) ISSN: 0730-3157
Conference Location: Milwaukee, WI, USA

Contact IEEE to Subscribe

References

References is not available for this document.