@article{ART001346197},
author={최일준 and 추병균 and Changsuk Oh},
title={Efficient Attack Traffic Detection Method for Reducing False Alarms},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2009},
volume={14},
number={5},
pages={65-75}
TY - JOUR
AU - 최일준
AU - 추병균
AU - Changsuk Oh
TI - Efficient Attack Traffic Detection Method for Reducing False Alarms
JO - Journal of The Korea Society of Computer and Information
PY - 2009
VL - 14
IS - 5
PB - The Korean Society Of Computer And Information
SP - 65
EP - 75
SN - 1598-849X
AB - The development of IT technology, Internet popularity is increasing geometrically. However, as its side effect, the intrusion behaviors such as information leakage for key system and infringement of computation network etc are also increasing fast. The attack traffic detection method which is suggested in this study utilizes the Snort, traditional NIDS, filters the packet with false positive among the detected attack traffics using Nmap information. Then, it performs the secondary filtering using nessus vulnerability information and finally performs correlation analysis considering appropriateness of management system, severity of signature and security hole so that it could reduce false positive alarm message as well as minimize the errors from false positive and as a result, it raised the overall attack detection results.
KW - Traffic Detection;DDos;Network-IDS;Snort
DO -
UR -
ER -
최일준, 추병균 and Changsuk Oh. (2009). Efficient Attack Traffic Detection Method for Reducing False Alarms. Journal of The Korea Society of Computer and Information, 14(5), 65-75.
최일준, 추병균 and Changsuk Oh. 2009, "Efficient Attack Traffic Detection Method for Reducing False Alarms", Journal of The Korea Society of Computer and Information, vol.14, no.5 pp.65-75.
최일준, 추병균, Changsuk Oh "Efficient Attack Traffic Detection Method for Reducing False Alarms" Journal of The Korea Society of Computer and Information 14.5 pp.65-75 (2009) : 65.
최일준, 추병균, Changsuk Oh. Efficient Attack Traffic Detection Method for Reducing False Alarms. 2009; 14(5), 65-75.
최일준, 추병균 and Changsuk Oh. "Efficient Attack Traffic Detection Method for Reducing False Alarms" Journal of The Korea Society of Computer and Information 14, no.5 (2009) : 65-75.
최일준; 추병균; Changsuk Oh. Efficient Attack Traffic Detection Method for Reducing False Alarms. Journal of The Korea Society of Computer and Information, 14(5), 65-75.
최일준; 추병균; Changsuk Oh. Efficient Attack Traffic Detection Method for Reducing False Alarms. Journal of The Korea Society of Computer and Information. 2009; 14(5) 65-75.
최일준, 추병균, Changsuk Oh. Efficient Attack Traffic Detection Method for Reducing False Alarms. 2009; 14(5), 65-75.
최일준, 추병균 and Changsuk Oh. "Efficient Attack Traffic Detection Method for Reducing False Alarms" Journal of The Korea Society of Computer and Information 14, no.5 (2009) : 65-75.