2012
DOI: 10.1007/978-3-642-33704-8_18
|View full text |Cite
|
Sign up to set email alerts
|

Limitation of Honeypot/Honeynet Databases to Enhance Alert Correlation

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
3

Citation Types

0
3
0

Year Published

2015
2015
2022
2022

Publication Types

Select...
4
1

Relationship

0
5

Authors

Journals

citations
Cited by 6 publications
(3 citation statements)
references
References 17 publications
0
3
0
Order By: Relevance
“…The previous remarks on the heterogeneity and complementarity of the information carried by alerts coming from different domains of an ICS suggest that our main objective is to enrich the information gathered from one domain with information from the other domain. In traditional alert correlation approaches [7,24,25], alert enrichment objective is to add some missing contextual information. Enrichment approaches often rely on knowledge bases [26] which might include information such as the system's topology [24] and assets [7].…”
Section: Alert Correlationmentioning
confidence: 99%
See 2 more Smart Citations
“…The previous remarks on the heterogeneity and complementarity of the information carried by alerts coming from different domains of an ICS suggest that our main objective is to enrich the information gathered from one domain with information from the other domain. In traditional alert correlation approaches [7,24,25], alert enrichment objective is to add some missing contextual information. Enrichment approaches often rely on knowledge bases [26] which might include information such as the system's topology [24] and assets [7].…”
Section: Alert Correlationmentioning
confidence: 99%
“…Enrichment approaches often rely on knowledge bases [26] which might include information such as the system's topology [24] and assets [7]. In the same vein, the approach in [25] uses honeypot databases for contextual information on malware propagation activity or the profile of web servers in order to enrich IDS alerts.…”
Section: Alert Correlationmentioning
confidence: 99%
See 1 more Smart Citation