False Positive Alerts Reduction by Correlating the Intrusion Detection System Alerts: Investigation 5tudy

Homam EI-Taj, Omar Abouabdalla, Ahmed Mansour Manasrah · Journal of Communication and Computer · 2010

Intrusion Detection System (IDS) is the most powerful system that can handle the intrusions of the computer environments by triggering alerts to make the analysts take actions to stop this intrusion, but the IDS is triggering alerts for any suspicious activity which means thousand alerts that the analysts should take care of it. These Alerts has different seventies and most of them don’t require big attention because of the huge number of the false alerts among them. Deleting the false alerts or reducing the amount of the alerts (false alerts or real alerts) from the entire amount alerts lead the researchers to create many methods such as the alert correlation which is this paper tries to investigate.

Read the paper · More papers on PaperTik