CONDOR: A Hybrid IDS to Offer Improved Intrusion Detection

DAY, David and FLORES, Denys (2012). CONDOR: A Hybrid IDS to Offer Improved Intrusion Detection. In: Third International Symposium on Mobile and Wireless Network Security (MWNS-12), Liverpool, 25-27th June 2012. (Submitted)

[img]
Preview
PDF - Accepted Version
Download (641kB) | Preview

    Abstract

    Intrusion Detection Systems are an accepted and very useful option to monitor, and detect malicious activities. However, Intrusion Detection Systems have inherent limitations which lead to false positives and false negatives; we propose that combining signature and anomaly based IDSs should be examined. This paper contrasts signature and anomaly-based IDSs, and critiques some proposals about hybrid IDSs with signature and heuristic capabilities, before considering some of their contributions in order to include them as main features of a new hybrid IDS named CONDOR (COmbined Network intrusion Detection ORientate), which is designed to offer superior pattern analysis and anomaly detection by reducing false positive rates and administrator intervention.

    Item Type: Conference or Workshop Item (Paper)
    Research Institute, Centre or Group: Cultural Communication and Computing Research Institute > Communication and Computing Research Centre
    Depositing User: David Day
    Date Deposited: 31 May 2012 10:53
    Last Modified: 31 May 2012 10:53
    URI: http://shura.shu.ac.uk/id/eprint/5246

    Actions (login required)

    View Item

    Downloads

    Downloads per month over past year

    View more statistics