An IDS Alert Aggregation Method Based on Clustering

Abstract:

Article Preview

How to aggregate and reduce duplicated alerts is one of the most important tasks in IDSs. This paper proposed an alert aggregation method, which clustering similar alerts into a hyper alert based on category and feature similarity. For each feature we define an appropriate similarity function. The overall similarity is weighted by a specifiable expectation of similarity. Experiments on DARPA2000 data set have demonstrated the effectiveness of this method.

Info:

Periodical:

Advanced Materials Research (Volumes 219-220)

Edited by:

Helen Zhang, Gang Shen and David Jin

Pages:

156-159

DOI:

10.4028/www.scientific.net/AMR.219-220.156

Citation:

Q. H. Zheng et al., "An IDS Alert Aggregation Method Based on Clustering", Advanced Materials Research, Vols. 219-220, pp. 156-159, 2011

Online since:

March 2011

Export:

Price:

$35.00

In order to see related information, you need to Login.

In order to see related information, you need to Login.