Using a Fuzzy Inference System to Reduce False Positives in Intrusion Detection

Georgios P. Spathoulas, Sokratis K. Katsikas · 2009

Even if intrusion detection systems have marginally improved in the past few years, they still face the problem of high false positives rate. In this paper we propose the use of a fuzzy inference system, which filters out false positives, without missing on any of the detected attacks. The design of the system is based on meta-alerts, which carry special information about the nature of alerts. The system has been tested against the DARPA dataset and has exhibited a significant reduction (83%) of false positives.

Read the paper · More papers on PaperTik