作者: Ulf E. Larson , Stefan Lindskog , Erland Jonsson
DOI:
关键词:
摘要: This chapter aims at providing a clear and concise picture of data collection for intrusion detection. It provides detailed explanation generic mechanism components the interaction with environment, from initial triggering to output log records. Taxonomies characteristics deployment considerations are provided discussed. Furthermore, guidelines hints selection provided. Finally, this presents set strategies determining what collect, it also discusses some challenges in field. An appendix classification 50 studied mechanisms is assisting detection system developers, designers, operators selecting resource efficient collection.