Enhancement Intrusion Detection using Alert Correlation in Co-operative Intrusion Detection Systems

Ali Ahmadian Ramaki, Reza Ebrahimi Atani, Reza Kazemi, Iman Abadi, Mohsen Tavaghoe · 2013

Increasing growth on employing computer networks services on the one hand and networks intrusion on the other hand have caused Intrusion Detection Systems (IDSs) to become a critical research subject in the area of computer systems security. To establish security in computer systems other administrations such as IDSs are required as well as firewalls and other intrusion prevention policies so as to be capable of detecting and dealing with intruders in case of breaking in through firewalls, antivirus and other security tools. The number of alerts generated by IDS, in some of cases, escalates over 2000 messages a day. A tremendous volume of alerts coupled with their low quality makes it challenging for a system administrator to handle intrusions in timely manner. It is hardly possible for systems security managers to handle such distributed alerts in order to increase their quality and convey a comprehensible report on current security state to security analyzer. One of the important approaches to handle such inefficiency is the employment of correlation of raw generated alerts by the system security sensors including IDSs. Such process aims at reduction of generated alerts as well as extraction of attacks scenario in CIDS environment. In this paper, we apply a probabilistic correlation algorithm that is works based on similarity between alerts on three standard data sets. The results indicate that the incoming alerts significantly reduced by this algorithm in rate of 99.96% on Treasure Hunt data set.

Read the paper · More papers on PaperTik