intrusion alerts
Recently Published Documents


TOTAL DOCUMENTS

36
(FIVE YEARS 1)

H-INDEX

10
(FIVE YEARS 0)

Author(s):  
Riyad AM

Abstract: Intrusion detection systems are the last line of defence in the network security domain. Improving the performance of intrusion detection systems always increase false positives. This is a serious problem in the field of intrusion detection. In order to overcome this issue to a great extend, we propose a multi level post processing of intrusion alerts eliminating false positives produced by various intrusion detection systems in the network. For this purpose, the alerts are normalized first. Then, a preliminary alert filtration phase prioritize the alerts and removes irrelevant alerts. The higher priority alerts are then aggregated to fewer numbers of hyper alerts. In the final phase, alert correlation is done and alert correlation graph is constructed for finding the causal relationship among the alerts which further eliminates false positives. Experiments were conducted on LLDOS 1.0 dataset for verifying the approach and measuring the accuracy. Keywords: Intrusion detection system, alert prioritization, alert aggregation, alert correlation, LLDOS 1.0 dataset, alert correlation graph.


IEEE Access ◽  
2020 ◽  
Vol 8 ◽  
pp. 108748-108765
Author(s):  
Egon Kidmose ◽  
Matija Stevanovic ◽  
Soren Brandbyge ◽  
Jens M. Pedersen
Keyword(s):  

Author(s):  
Aymen Akremi ◽  
Hassen Sallay ◽  
Mohsen Rouached

Investigators search usually for any kind of events related directly to an investigation case to both limit the search space and propose new hypotheses about the suspect. Intrusion detection system (IDS) provide relevant information to the forensics experts since it detects the attacks and gathers automatically several pertinent features of the network in the attack moment. Thus, IDS should be very effective in term of detection accuracy of new unknown attacks signatures, and without generating huge number of false alerts in high speed networks. This tradeoff between keeping high detection accuracy without generating false alerts is today a big challenge. As an effort to deal with false alerts generation, the authors propose new intrusion alert classifier, named Alert Miner (AM), to classify efficiently in near real-time the intrusion alerts in HSN. AM uses an outlier detection technique based on an adaptive deduced association rules set to classify the alerts automatically and without human assistance.


Author(s):  
Joseph Mbugua Chahira ◽  
Jane Kinanu Kiruki ◽  
Peter Kiprono Kemei
Keyword(s):  

Sign in / Sign up

Export Citation Format

Share Document