Scalable Alerts Modelling and Threat Assessment

Xing Li · 2007

Alerts correlation is useful for intrusion detection systems. A new model to correlate and analyze alerts is proposed in this paper, focusing on the scalability and practicability. Making use of information such as IP address and time stamp, this alerts model can partition and condense the flood of alerts, reflecting the attack episodes. Then based on the alerts model, a method is designed to assess the threat of malicious activities on networks. The evaluation on real IDS alerts validates the reasonability of the alerts model and effectiveness of the threat assessment method.

Read the paper · More papers on PaperTik