A survey and taxonomy of techniques used for alerts of Intrusion Detection Systems
Mohamed Amine Agalit, Youness Idrissi Khamlichi, El Mostapha Chakir · 2019
Over the years, Intrusion detection systems IDSs have evolved to handle many types of threats. Nowadays, network security administrators expect IDSs to monitor networks and hosts and identify suspicious activities. IDSs must be configured to recognize abnormal behavior but may still generate thousands of alerts daily, distinguishing between the important alerts and the irrelevant ones (i.e., false positives) are more complicated for the security administrators. This weakness has led to the emergence of many methods in which to deal with these alerts. The aim of conducted research in this field is to propose different techniques to handle the alerts, to reduce them and distinguish real attacks from false positives and low importance events. This paper is a survey that represents a review of the current research related to the false positives problem.