IHFM: An Improved Hierarchical Filtering Method for Multi-source malicious alerts

Gengxin Li, Hui Li, Xin She Yang · 2021

Network security situation awareness has recently emerged as a game changer in the security landscape due to its proven potential to help security managers accurately control the system status in real time. However, the exiting method suffer from a large number of misjudgments in the active defense mechanism established based on the alarm data when deal with the huge massive threat logs and event information.Therefore, the method filtering huge warning logs with a fine granularity becomes one of the key problem, which is the basis for the accuracy of the subsequent security situation assessment algorithm. Experiments show that hierarchical filtering performs well for screening of alarm events. In this paper, we propose a five-layer filtering model named IHFM to flexibility filter a large number of alarms in an efficient way. Besides, to further improve the accuracy of model filtering, we propose a concept of the difference in joint performance entropy and introduce the FAHP algorithm to calculate its weight parameters. Lastly, the comparative analysis with experiments in real network environment proves that our proposed method classify and filter malicious events accurately with high flexibility while guaranteeing low false alarm rate.

Read the paper · More papers on PaperTik