A Stream Clustering Algorithm for Classifying Network IDS Alerts
Risto Vaarandi · 2021
Network IDS is a widely used security monitoring technology for detecting cyber attacks, malware activity, and other unwanted network traffic. Unfortunately, network IDSs are known to generate a large number of alerts which overwhelm the human analyst, with many alerts having low importance or being false positives. This paper addresses this issue and proposes a lightweight stream clustering algorithm for classifying IDS alerts and discovering frequent attack scenarios.