Intrusion-Alert Normalization using Attack-related Database
Divya Gupta Bhawna Gupta, Nidhi Chauhan Surabhi Singh · CiiT international journal of networking and communication engineering · 2015
In the present scenario, there are various kinds of intrusion alerts which are stored using different styles and presentation having dissimilar interpretation. These alerts can be converted to single format using various protocols such as SNMP trap, syslog protocol, IDMEF, IDXP etc. The presence of different formats makes it difficult to use that together. We need the normalization process to unify alerts from a variety of security-related equipment. This article describes how to normalize alerts from several IDS and security-related equipment.