Clustering of Snort alerts to identify patterns and reduce analyst workload
Richard Harang, Peter Guarino · 2012
Pattern-matching intrusion detection system (IDS) tools such as Snort are known to generate an extremely large number of alerts. To address this problem, we present a greedy aggregation algorithm that efficiently reduces multiple alerts by grouping the raw output of IDS tools into `meta-alerts' that contain common information. In contrast to the current thrust of alert aggregation efforts, our approach does not require developing elaborate semantic structures for capturing information, nor creating and maintaining an external database containing information on attack vectors, network topologies, and cause-and-effect relationships. We apply our method to 30 days of Snort alerts, grouped by hour, and observe that we can reduce the number of analyst-visible Snort alerts by up to 99.5%, with an average reduction of approximately 83.2%.