False Alert Reduction on Network-Based Intrusion Detection Systems by Means of Feature Frequencies

Sara Khanchi, Fazlollah Adibnia · 2009

Internet grows day to day and so on the complexity of its security. Different types of people all around the world use Internet in their daily routine tasks. Internet and network security challenges make use of more efficient and complicated defense tools such as Intrusion Detection Systems (IDSs) vital. Nowadays attempts to solve IDS problems are under consideration. One of the deficiencies of current commercial IDSs is huge number of alerts. Most of generated IDS alerts are related to benign events which overwhelm the analyst. In this paper we try to reduce number of IDS false alerts and filter out those with high scores to decrease analyst workload. Our approach is evaluated on DARPA 2000 dataset and its efficiency has been shown.

Read the paper · More papers on PaperTik