An alert aggregation algorithm based on MapReduce Parallel computing model
LU Song-nian · Information technology newsletter · 2011
With the rapid growth of viruses,network attacks and the network traffic,analyzing the huge log and alert information generated by intrusion detection system would face the increasing challenges.The MapReduce programming model is inspired by Google and targets data-intensive parallel computations.The paper presents and implements a high-performance alert aggregation algorithm based on MapReduce parallel computing model.The experiment results on the DARPA 2000 dataset showed that this algorithm is effective and efficient.