Publication:
An IDS rule redundancy verification

dc.contributor.authorPiyawat Noiprasongen_US
dc.contributor.authorAssadarat Khuraten_US
dc.contributor.otherMahidol Universityen_US
dc.date.accessioned2021-02-03T06:22:20Z
dc.date.available2021-02-03T06:22:20Z
dc.date.issued2020-11-04en_US
dc.description.abstractCopyright © JCSSE 2020 - 17th International Joint Conf. on Computer Science and Software Engineering. Intrusion Detection System (IDS) is a network security software and hardware widely used to detect anomaly network traffics by comparing the traffics against rules specified beforehand. Snort is one of the most famous open-source IDS system. To write a rule, Snort specifies structure and values in Snort manual. This specification is expressive enough to write in different way with the same meaning. If there are rule redundancy, it could distract performance. We, thus, propose a proof of semantical issues for Snort rule and found four pairs of Snort rule combinations that can cause redundancy. In addition, we create a tool to verify such redundancy between two rules on the public rulesets from Snort community and Emerging threat. As a result of our test, we found several redundancy issues in public rulesets if the user enables commented rules.en_US
dc.identifier.citationJCSSE 2020 - 17th International Joint Conference on Computer Science and Software Engineering. (2020), 110-115en_US
dc.identifier.doi10.1109/JCSSE49651.2020.9268269en_US
dc.identifier.other2-s2.0-85098514714en_US
dc.identifier.urihttps://repository.li.mahidol.ac.th/handle/123456789/60908
dc.rightsMahidol Universityen_US
dc.rights.holderSCOPUSen_US
dc.source.urihttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85098514714&origin=inwarden_US
dc.subjectComputer Scienceen_US
dc.subjectDecision Sciencesen_US
dc.titleAn IDS rule redundancy verificationen_US
dc.typeConference Paperen_US
dspace.entity.typePublication
mu.datasource.scopushttps://www.scopus.com/inward/record.uri?partnerID=HzOxMe3b&scp=85098514714&origin=inwarden_US

Files

Collections