Use of host's software information to mitigate false positive in signature-based NIDS

LONG Xiao-fei,FENG Yan,WANG Rui-jie
DOI: https://doi.org/10.3969/j.issn.1000-7024.2007.03.016
2007-01-01
Abstract:For lackness of knowledge about the context of network hosts,most signature-based NIDSs produce too many false positives,which prevent the administrators from focusing their efforts on real dangerous alerts quickly.A mechanism in NIDS is proposed,which makes a decision before pattern matching to filter unnecessary intrusion rules for matching,by utilizing the software information of the target hosts,to mitigate false positives drastically.This method is implemented in the prototype system.The result of testing on typical intranet shows that this method surely mitigate false positives and improve quality of alerts in NIDS.
What problem does this paper attempt to address?