Mohamed, Ashara Banu and Idris, Norbik Bashah and Shanmugum, Bharanidharan (2012) Alert correlation framework using a novel clustering approach. In: 2012 International Conference on Computer and Information Science, ICCIS 2012 - A Conference of World Engineering, Science and Technology Congress, ESTCON 2012 - Conference Proceedings. IEEE, New York, USA, pp. 403-408. ISBN 978-146731938-6
Full text not available from this repository.
Official URL: http://dx.doi.org/10.1109/ICCISci.2012.6297279
Abstract
Currently, the primary and pressing issue in IDS implementation is the enormous number of alerts generated by the IDS sensors. Moreover, due to this obtrusive predicament, two other problems have emerged, first is the difficulty in processing the alerts accurately and second is the reduction in performance rate in terms of time and memory capacity while processing these alerts. The purpose of this research is to construct a holistic solution that is able to firstly reduce the number of alerts to be processed and at the same time produce a high quality attack scenarios that are meaningful to the administrators in a timely manner. To achieve these goals, alerts generated by IDS sensors need to be correlated and organized in an appropriate approach. Thus the significant contribution of this research is to create an integrated operational framework for alert processing that reduces the amount of alerts to be processed and creates more meaningful attack scenarios to be analyzed. We are presenting the results obtained from the clustering algorithm and discuss its significant contribution to practitioners in an actual working environment.
Item Type: | Book Section |
---|---|
Additional Information: | Indexed by Scopus |
Uncontrolled Keywords: | clustering, hashing technique, IDS |
Subjects: | Q Science > QA Mathematics > QA75 Electronic computers. Computer science |
Divisions: | Advanced Informatics School |
ID Code: | 34272 |
Deposited By: | INVALID USER |
Deposited On: | 30 Sep 2013 07:40 |
Last Modified: | 02 Feb 2017 05:53 |
Repository Staff Only: item control page