首页> 外文会议>International Conference on Mining Intelligence and Knowledge Exploration >An Improved Intrusion Detection System Based on a Two Stage Alarm Correlation to Identify Outliers and False Alerts
【24h】

An Improved Intrusion Detection System Based on a Two Stage Alarm Correlation to Identify Outliers and False Alerts

机译:基于两个阶段报警相关的改进的入侵检测系统,以识别异常值和误报

获取原文
获取外文期刊封面目录资料

摘要

To ensure the protection of computer networks from attacks, an intrusion detection system (IDS) should be included in the security architecture. Despite the detection of intrusions is the ultimate goal, IDSs generate a huge amount of false alerts which cannot be properly managed by the administrator, along with some noisy alerts or outliers. Many research works were conducted to improve IDS accuracy by reducing the rate of false alerts and eliminating outliers. In this paper, we propose a two-stage process to detect false alerts and outliers. In the first stage, we remove outliers from the set of meta-alerts using the best outliers detection method after evaluating the most cited ones in the literature. In the last stage, we propose a binary classification algorithm to classify meta-alerts whether as false alerts or real attacks. Experimental results show that our proposed process outperforms concurrent methods by considerably reducing the rate of false alerts and outliers.
机译:为了确保从攻击中保护计算机网络,应将入侵检测系统(ID)包含在安全架构中。尽管入侵的检测是最终目标,但IDSS会生成大量的错误警报,管理员无法正确管理,以及一些嘈杂的警报或异常值。通过降低虚假警报和消除异常值,进行了许多研究工作以提高IDS准确性。在本文中,我们提出了一个两阶段的过程来检测假警报和异常值。在第一阶段,我们使用最佳的异常值检测方法在评估文献中最引用的阶段之后,从Meta-Alerges集中删除异常值。在最后阶段,我们提出了一种二进制分类算法,以对Meta-Alers进行分类,无论是假警报还是真实攻击。实验结果表明,我们提出的过程通过大大降低了虚假警报和异常值的速度来优异地优于并发方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号