A comparative study of alert correlations for intrusion detection

Leau, Yu Beng and Tan , Soo Fun and Ramadass. S. , and Manickam S., (2014) A comparative study of alert correlations for intrusion detection. Proceedings - 2013 International Conference on Advanced Computer Science Applications and Technologies, ACSAT 2013 . pp. 85-88.

[img]
Preview
PDF
42Kb

Official URL: http://dx.doi.org/10.1109/ACSAT.2013.24

Abstract

The prevalent use of computer applications and communication technologies has rising the numbers of network intrusion attempts. These malicious attempts including hacking, botnets and works are pushing organization networks to a risky atmosphere where the intruder tries to compromise the confidentiality, integrity and availability of resources. In order to detect these malicious activities, Intrusion Detection Systems (IDSs) have been widely deployed in corporate networks. IDSs play an important role in monitoring traffic behaviors in a computer network, identifying the anomalous activity and notifying the security analyst with current network status. Unfortunately, one of the IDSs' drawbacks is they produce a large number of false positives and non-relevant positives alerts that could overwhelm the security analyst. Therefore, the process of analyzing alerts in order to provide a more synthetic and high-level view of the attempted intrusions is needed. This process is called Alert Correlation. In this paper, we present commonly used alert correlation approaches and highlight their advantages and disadvantages from various perspectives. Subsequently, we summarize some current alert correlation models with their alert correlation approach.

Item Type:Article
Uncontrolled Keywords:Alert Correlatios; Anomaly Detection; Intrusion Detection System; Misuse Detection
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
ID Code:10157
Deposited By:IR Admin
Deposited On:06 Feb 2015 09:53
Last Modified:16 Feb 2015 11:26

Repository Staff Only: item control page


Browse Repository
Collection
   Articles
   Book
   Speeches
   Thesis
   UMS News
Search
Quick Search

   Latest Repository

Link to other Malaysia University Institutional Repository

Malaysia University Institutional Repository