{"title":"Research on Preprocessing Technique of Alert Aggregation","authors":"C. Mu, Bing Shuai","doi":"10.1109/CSO.2012.136","DOIUrl":null,"url":null,"abstract":"In order to solve the problems caused by repetitive IDS alerts, an adaptive alert aggregation approach is proposed in this paper. According to the corresponding alert types, the stay times of aggregate alerts in the buffer area can be adjusted automatically so that the repetitive alerts can be aggregated effectively. The experiments results indicate that by using the adaptive alert aggregation model, the problems caused by repetitive alerts are solved, and a balance between alert amount and alert type is achieved at the same time. As a result, the adaptive alert aggregation approach not only can provide a strong support for the further alert processing in IDAM &IRS but also can balance the speed and security of a network system.","PeriodicalId":170543,"journal":{"name":"2012 Fifth International Joint Conference on Computational Sciences and Optimization","volume":"296 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-06-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Fifth International Joint Conference on Computational Sciences and Optimization","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CSO.2012.136","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3
Abstract
In order to solve the problems caused by repetitive IDS alerts, an adaptive alert aggregation approach is proposed in this paper. According to the corresponding alert types, the stay times of aggregate alerts in the buffer area can be adjusted automatically so that the repetitive alerts can be aggregated effectively. The experiments results indicate that by using the adaptive alert aggregation model, the problems caused by repetitive alerts are solved, and a balance between alert amount and alert type is achieved at the same time. As a result, the adaptive alert aggregation approach not only can provide a strong support for the further alert processing in IDAM &IRS but also can balance the speed and security of a network system.