Alarm clustering for intrusion detection systems in network
Zhao Zeng-yi · Computers & Security · 2008
Until recently,network administrators manually arranged alarms produced by intrusion detection systems (IDS) to attain a high-level description. For fusing multi-kinds of IDS alerts can effectively improve warning veracity,automatic tools for alarm clustering have been proposed to provide such a high-level description of the attack scenarios. In addition,it has been shown that effective threat analysis requires the fusion of different sources of information,such as different IDS. This paper proposes a new alarm clustering system to perform alarm clustering which produces unified descriptions of attacks from alarms produced by multiple IDS. Experimental results show that the high-level alarms produced by the alarm clustering module effectively summarize the attacks,drastically reducing the volume of alarms presented to the administrator. In addition,these high-level alarms can be used as the base to perform further higher-level threat analysis.