TY - BOOK AU - AU - ED - SpringerLink (Online service) TI - Understanding Intrusion Detection Through Visualization T2 - Advances in Information Security, SN - 9780387276366 AV - Libro electrónico U1 - 005.82 23 PY - 2006/// CY - Boston, MA PB - Springer US KW - Computer science KW - Computer Communication Networks KW - Data structures (Computer science) KW - Data encryption (Computer science) KW - Computer vision KW - Optical pattern recognition KW - Computer Science KW - Data Encryption KW - Computer Imaging, Vision, Pattern Recognition and Graphics KW - Pattern Recognition KW - Data Structures, Cryptology and Information Theory N1 - An Introduction to Intrusion Detection -- The Base-Rate Fallacy and the Difficulty of Intrusion Detection -- Visualizing Intrusions: Watching the Webserver -- Combining a Bayesian Classifier with Visualization: Understanding the IDS -- Visualizing the Inner Workings of a Self Learning Classifier: Improving the Usability of Intrusion Detection Systems -- Visualization for Intrusion DetectionHooking the Worm -- Epilogue; ZDB-2-SCS N2 - With the ever increasing use of computers for critical systems, computer security that protects data and computer systems from intentional, malicious intervention, continues to attract significant attention. Among the methods for defense, the application of a tool to help the operator identify ongoing or already perpetrated attacks (intrusion detection), has been the subject of considerable research in the past ten years. A key problem with current intrusion detection systems is the high number of false alarms they produce. Understanding Intrusion Detection through Visualization presents research on why false alarms are, and will remain a problem; then applies results from the field of information visualization to the problem of intrusion detection. This approach promises to enable the operator to identify false (and true) alarms, while aiding the operator to identify other operational characteristics of intrusion detection systems. This volume presents four different visualization approaches, mainly applied to data from web server access logs. Understanding Intrusion Detection through Visualization is structured for security professionals, researchers and practitioners. This book is also suitable for graduate students in computer science UR - http://dx.doi.org/10.1007/0-387-27636-X ER -