ALERT Generation Intrusion Detection System on Heterogeneous System

IOSR Journal of Business and Management (IOSR - JBM), Journal No. 46879, UGC Serial No. 2953, Impact Factor - 3.52, pp 51 - 61, e-ISSN - 2278 - 487X, p-ISSN - 2319 - 7668, IOSR.

11 Pages Posted: 26 May 2020 Last revised: 23 Jun 2020

See all articles by Siddhartha Chatterjee

Siddhartha Chatterjee

Maulana Abul Kalam Azad University of Technology

Date Written: June 17, 2018

Abstract

Security is one of the most fundamental concerns in today’s Enterprise network. An enterprise is composed of heterogeneous entities having varying asset values and attack vulnerabilities. To protect the information resources in an enterprise, packet filtering based firewall rules are deployed and the same time, to detect potential threats in the systems and network, intrusion detection systems are also deployed.

In a general enterprise, set up these two activities are performed independently. But it was shown in the literature that the dynamic configuration of firewall rules can be achieved through utilization of the alerts generated by the IDS tools. However, the IDS systems normally generates large number of alerts that results in blocking of a large number of sites by the firewalls.

In this work we propose a mechanism by which firewall rules are updated by capturing the alerts generated by IDS, but the sites are not blocked for all the information resources. Whether a site will be blocked for an information resource depends on Risk Rate of the resource. If the Risk Rate for an information resource exceeds a predefined threshold value then the site will be blocked for that particular resource. However the site will be available to all other resources having Risk Rate less than the threshold value. This includes the user experience of the network without using the attack vulnerabilities.


Keywords: IDS, Snort, Firewall, Risk Management, Asset Management.

JEL Classification: C61

Suggested Citation

Chatterjee, Siddhartha, ALERT Generation Intrusion Detection System on Heterogeneous System (June 17, 2018). IOSR Journal of Business and Management (IOSR - JBM), Journal No. 46879, UGC Serial No. 2953, Impact Factor - 3.52, pp 51 - 61, e-ISSN - 2278 - 487X, p-ISSN - 2319 - 7668, IOSR., Available at SSRN: https://ssrn.com/abstract=3586440

Siddhartha Chatterjee (Contact Author)

Maulana Abul Kalam Azad University of Technology ( email )

West Bengal
India

Do you have a job opening that you would like to promote on SSRN?

Paper statistics

Downloads
70
Abstract Views
529
Rank
875,328
PlumX Metrics