Adaptive IDS Alerts Correlation according to the traffic type and the attacks properties
Meharouech Sourour, Adel Bouhoula, Abbes Tarek · 2009
Different network security solutions exist and contribute to enhanced security. From these solutions, Intrusion detection systems (IDS) have become one of the most common countermeasures for monitoring safety in computer systems and networks. However, In order to address these limitations, the paper presents a fast and efficient system classifying alerts into true positives and false positives and formulating more general alerts based on individual true positives. based on an adaptive alerts correlation.