Anomaly-based network IDS false alarm filter using cluster-based alarm classification approach

Qais Saif Qassim, Abdullah Mohd Zın, Mohd Juzaiddin Ab Aziz · International Journal of Security and Networks · 2016

Anomaly-based network intrusion detection systems (A-NIDS) are an important and essential defence mechanism against network attacks. However, they generate a high volume of alarms that can be mixed with false-positive alarms, which poses a major challenge for these systems. Large amounts of false alarms prevent correct detection and make an immediate response impossible for intrusion detection system (IDS). To mitigate this issue, this paper presents a strategy for filtering these alarms to reduce the rate of false-positive alarms of A-NIDS. This paper presents a new semi-supervised alarm classification method that does not require predefined knowledge of attack signatures or security personal feedback.

Read the paper · More papers on PaperTik