Classification of intrusion detection alerts using abstaining classifiers
Tadeusz Pietraszek · Intelligent Data Analysis · 2007
Intrusion Detection Systems have been observed to trigger an abundance of false positives, that is alerts not reporting security problems. Assuming that in real installations most of the alerts are reviewed by human security analysts in a timely mann