A Method for Network Attack Events Analysis Based on Log Attribute Similarity

Xiaoxiao Ren, Junyong Luo, Meijuan Yin, Wu-ping Chen · International Conference on Multimedia Information Networking and Security · 2013

In order to solve the problem that the alert logs of network security devices are always redundant, this paper proposes a new approach to detect network attack events based on attribute similarity, which aggregates and correlates alerts in IDS logs. Firstly, we analyze the IDS logs and extract the important attributes. Secondly, we define the threshold and method to calculate the similarity of attributes. Finally, we obtain network attack e vents with the aggregation and correlation algorithm. The experiment results show that our approach is more effective and efficient in aggregating a mass of alerts compared to previous work in the area.

Read the paper · More papers on PaperTik