Aggregating IDS Alerts Based on Time Threshold: Testing and Results

Homam Reda El-Taj · INTERNATIONAL JOURNAL OF COMPUTERS & TECHNOLOGY · 2013

Every secure system has the possibility to fail. Therefore, extra effort should be taken to protect these systems. Intrusion Detection Systems (IDSs) had been proposed with the aim of providing extra protection to security systems. These systems trigger thousands of alerts per day, which prompt security analysts to verify each alert for relevance and severity based on an aggregation criterion. Several aggregation methods have been proposed to collect these alerts. This paper presents our threshold aggregation system (TAS). Results shows that TAS aggregates IDS alerts accurately based on user demands and threshold value.

Read the paper · More papers on PaperTik