CoreFlow: Enriching Bro security events using network traffic monitoring data

@article{Koning2018CoreFlowEB,
  title={CoreFlow: Enriching Bro security events using network traffic monitoring data},
  author={Ralph Koning and Nick Buraglio and Cees T. A. M. de Laat and Paola Grosso},
  journal={Future Generation Comp. Syst.},
  year={2018},
  volume={79},
  pages={235-242}
}
Attacks against network infrastructures can be detected by Intrusion Detection Systems (IDS). Still reaction to these events are often limited by the lack of larger contextual information in which they occurred. In this paper we present CoreFlow, a framework for the correlation and enrichment of IDS data with network flow information. CoreFlow ingests data from the Bro IDS and augments this with flow data from the devices in the network. By doing this the network providers are able to… CONTINUE READING
Recent Discussions
This paper has been referenced on Twitter 1 time over the past 90 days. VIEW TWEETS