Processing Intrusion Detection Alerts in Large-scale Network

Dong Li, Zhitang Li, Jie Ma · 2008

Intrusion detection system will produce large numbers of alerts, most of which are fasle positives. This paper wants to associate multiple intrusion detection systems in large-scale network to reduce overwhelming false alerts and discover real security events in real time. For processing these alerts, two algrithms named reduce and cluster will be developed in this paper, which can remove false alerts with a remarkable periodicity and can cluster multiple homogeneous alerts into one respectively. Experiment shows that over 90% of raw alerts will be filtered and less than 1% of the quantity will remain for analyst to process thoroughly.

Read the paper · More papers on PaperTik