首页> 外文会议>Computer Security Applications Conference >Mining Alarm Clusters to Improve Alarm Handling Efficiency
【24h】

Mining Alarm Clusters to Improve Alarm Handling Efficiency

机译:采矿报警群提高报警处理效率

获取原文

摘要

It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. As a matter of fact, we have been asked by one of our service divisions to help them deal with this problem. This paper presents the results of our research, validated thanks to a large set of operational data. We show that alarms should be managed by identifying and resolving their root causes. Alarm clustering is introduced as a method that supports the discovery of root causes. The general alarm clustering problem is proved to be NP-complete, an approximation algorithm is proposed, and experiments are presented.
机译:众所周知的问题是,通过每天触发数千次警报,入侵检测系统超载其人工操作者。事实上,我们的一位服务部门已经提出了,帮助他们处理这个问题。本文介绍了我们研究的结果,验证了一系列的操作数据。我们表明应通过识别和解决根本原因来管理警报。引入警报群集作为支持根本原因发现的方法。总则报警聚类问题被证明是NP完整的,提出了一种近似算法,并提出了实验。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号