Heterogeneous Fusion of IDS Alerts for Detecting DOS Attacks
Vrushank Shah, A. K. Aggarwal · 2015
Denial of Service (DOS) attacks is a situation in attacker tries to prevent the user of a particular service from using that service. Intrusion detection system is more efficient compared to firewalls in detecting DOS attack generated due to internal traffic. However, single IDS system usually fails in detecting novel attack and produces larger false alerts. This paper proposes a method for heterogeneous alert fusion for detection of DOS attacks. The proposed method shows increase in the detection rate of about 20% compared to signature based IDS and 10% compared to anomaly based IDS. On the other hand the False alarm rate reduces by 40%. Alert fusion results for two redundant IDS as well as two complementary IDS have been demonstrated.