The methods of decreasing FP in Anomaly based Intrusion Prevent System by using of complex information about information system

Authors

  • Anton Kudin Igor Sikorsky Kyiv Polytechnic Institute, Ukraine, Ukraine
  • Olga Grigorieva National Technical University of Ukraine "Igor Sikorsky Kyiv Polytechnic Institute", Ukraine
  • Svitlana Nosok

DOI:

https://doi.org/10.20535/tacs.2664-29132024.1.296412

Abstract

The main aim of this work is to optimize the efficiency of intrusion detection using complex analysis of indicators in information system by reducing the number of false positives, as well as the development of a universal technique for such optimization. Using laboratory environment with installed SIEMs Wazuh and Splunk we test the proposed optimization methods and proposed newly methodic for decreasing rating false/positive for some intrusion detecting systems.

Downloads

Published

2024-12-16

Issue

Section

Mathematical methods, models and technologies for secure cyberspace functioning research