Design and implementation of distributed IDS alert aggregation model

Min Yu · Jisuanji yingyong yanjiu · 2009

The article proposed a distributed alert aggregation model,composed of local component and network component.Local components transform raw alerts originating from traditional IDS to IDMEF-based alerts with uniform format,which were sent to network components.Network components aggregate similar alerts into a meta-alert,using an aggregation algorithm based on feature similarity computation.Multiple kinds of messages were proposed to meet the demands of the communication between the components and realized information share in the whole network.It′s economical to construct a distributed IDS under the model.

Read the paper · More papers on PaperTik