首页> 外文会议>International conference on mining intelligence and knowledge exploration >An Improved Intrusion Detection System Based on a Two Stage Alarm Correlation to Identify Outliers and False Alerts
【24h】

An Improved Intrusion Detection System Based on a Two Stage Alarm Correlation to Identify Outliers and False Alerts

机译:改进的基于两级警报关联的入侵检测系统,用于识别异常值和虚假警报

获取原文

摘要

To ensure the protection of computer networks from attacks, an intrusion detection system (IDS) should be included in the security architecture. Despite the detection of intrusions is the ultimate goal, IDSs generate a huge amount of false alerts which cannot be properly managed by the administrator, along with some noisy alerts or outliers. Many research works were conducted to improve IDS accuracy by reducing the rate of false alerts and eliminating outliers. In this paper, we propose a two-stage process to detect false alerts and outliers. In the first stage, we remove outliers from the set of meta-alerts using the best outliers detection method after evaluating the most cited ones in the literature. In the last stage, we propose a binary classification algorithm to classify meta-alerts whether as false alerts or real attacks. Experimental results show that our proposed process outperforms concurrent methods by considerably reducing the rate of false alerts and outliers.
机译:为了确保保护计算机网络免受攻击,安全体系结构中应包括入侵检测系统(IDS)。尽管检测到入侵是最终目标,但IDS会生成大量错误警报,这些警报无法被管理员正确管理,同时还会产生一些嘈杂的警报或异常值。为了减少错误警报的发生率并消除异常值,进行了许多研究工作以提高IDS的准确性。在本文中,我们提出了一个分为两个阶段的过程来检测错误警报和离群值。在第一阶段,我们在评估文献中引用次数最多的信息后,使用最佳离群值检测方法从元警报集中删除离群值。在最后阶段,我们提出了一种二进制分类算法,将元警报分类为错误警报还是真实攻击。实验结果表明,通过显着降低错误警报和异常值的发生率,我们提出的过程优于并行方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号