A Quality Framework to Improve IDS Performance Through Alert Post-Processing

Ali Riyad, Mohammed Ahmed, Husni Almistarihi · International journal of intelligent engineering and systems · 2019

An intrusion detection system is one of the network security tools installed to monitor suspicious activity in the network and act as a last line of defense.It normally notifies about the skeptical activity occurred in the network using sensors by sending alarms to the administrator.However, the IDS present in the large network generates not only a large number of alerts but also abundant false alerts.These generated alerts are very difficult to handle as it increases the burden for the network administrator and also pulls down the performance of the defense system.In order to overcome the issue, various countermeasures have been proposed.Commonly, to increase the quality of alerts, the alerts are post-processed in such a way that the false alerts are filtered out thereby refining the performance of the IDS defense.In this paper, we propose an IDS quality framework using alert post-processing techniques to separate out the false alerts generated by various sensors in the network.At low level alert post-processing, the priority scores are assigned based on the quality measures to filter the irrelevant alerts having less significance.At high level alert postprocessing, higher level operations such as alert aggregation, clustering, and hyper alert correlation have been carried out to minimize the number of alerts and the high level report consisting of significant alerts is presented to the administrator.Experiments have been conducted using DARPA 2000 dataset to assess the performance of the proposed system.The system has produced pleasing results than many of the existing methods with 95% of alert reduction rate, 99% of completeness and 100% of soundness towards enlightening the quality of the alerts generated by the IDS.

Read the paper · More papers on PaperTik