• Search Research Projects
  • Search Researchers
  • How to Use
  1. Back to previous page

Reducing false negative/false positive of IDS/IPS based on formal definition of attacks

Research Project

Project/Area Number 17500032
Research Category

Grant-in-Aid for Scientific Research (C)

Allocation TypeSingle-year Grants
Section一般
Research Field Computer system/Network
Research InstitutionChiba University

Principal Investigator

IMAIZUMI Takashi  Chiba University, Institute of Media and Information Technology, Associate Professor (70242287)

Project Period (FY) 2005 – 2007
Project Status Completed (Fiscal Year 2007)
Budget Amount *help
¥3,700,000 (Direct Cost: ¥3,400,000、Indirect Cost: ¥300,000)
Fiscal Year 2007: ¥1,300,000 (Direct Cost: ¥1,000,000、Indirect Cost: ¥300,000)
Fiscal Year 2006: ¥1,100,000 (Direct Cost: ¥1,100,000)
Fiscal Year 2005: ¥1,300,000 (Direct Cost: ¥1,300,000)
KeywordsInternet Security / Intrusion Detection / Prevention System / IDS / IPS / 誤検知 / False Positive q / 侵入検知システム / 侵入遮断システム / False Positive
Research Abstract

It is important far Intrusion Detection/Prevention Systems to reduce false alerts. If the system makes alerts for ordinary activities, administrators must check the existence of actual intrusions. We found that the differences of recognition among producer of IDS and user of IDS make these false alerts. We researched on how to represent threats that the users consider to be reported.
The users of the system consider alerts as false alerts when the detection result is different from the one expected. They judge it according to their own vague senses. It is very difficult to express such a vague demand strictly using description languages similar to programming languages. We found that the technique of the requirements analysis in software engineering is useful to express a vague demand. We define the notation of threats using the technique found in software engineering area. We use post conditions to describe threats, so we can' t use this for IDS/IPS configurations. However, we can evaluate IDS systems by comparing ratios of false alerts.

Report

(4 results)
  • 2007 Annual Research Report   Final Research Report Summary
  • 2006 Annual Research Report
  • 2005 Annual Research Report
  • Research Products

    (2 results)

All 2007

All Presentation (2 results)

  • [Presentation] IDSの誤検知除去に対するソフトウェア工学的アプローチ2007

    • Author(s)
      淡路 淳・今泉 貴史
    • Organizer
      情報処理学会 分散システム/インターネット運用技術研究会
    • Place of Presentation
      山梨県立大学
    • Year and Date
      2007-09-21
    • Description
      「研究成果報告書概要(和文)」より
    • Related Report
      2007 Annual Research Report 2007 Final Research Report Summary
  • [Presentation] Software engineering approach to eliminate false alerts of IDS systems2007

    • Author(s)
      AWAJI Jun, IMAIZUMI Takashi
    • Organizer
      DSM Research group, IPSJ.
    • Place of Presentation
      Yamanashi prefectural university
    • Year and Date
      2007-09-21
    • Description
      「研究成果報告書概要(欧文)」より
    • Related Report
      2007 Final Research Report Summary

URL: 

Published: 2005-04-01   Modified: 2016-04-21  

Information User Guide FAQ News Terms of Use Attribution of KAKENHI

Powered by NII kakenhi