Cooperative Alert-Filers for Network Surveillance
Joshua Ojo Nehinbe · 2010
Intrusion aggregation techniques fundamentally focus on how to reduce redundant alerts to lessen the workload of human analysts. Consequently, the clarity and inherent meanings of the entire alerts are completely suppressed. These mostly occur whenever attackers overload intrusion detectors with closely related digression packets that subsequently flood human analysts with lots of redundant alerts. Thus, the distributions of the alerts from heterogeneous sources suddenly overlap. Essentially, realistic evidence to differentiate false alerts from true positives becomes so complex to understand. Accordingly, network administrators erroneously concentrate on false attacks instead of realistic attacks and ultimately, several attacks easily elude detections. For these reasons, we implemented clustering method to investigate these problems using six evaluative data. Equivalent and unique rules were designed to filter intrusive alerts and to subsequently establish their distributions. Furthermore, the results obtained unmasked all the attacks and further revealed distributions of their alerts in realistic and synthetic networks.