Universiti Teknologi Malaysia Institutional Repository

Enhanced framework for alert processing using clustering approach based on artificial immune system

Mohamed, Ashara Banu (2015) Enhanced framework for alert processing using clustering approach based on artificial immune system. PhD thesis, Universiti Teknologi Malaysia, Faculty of Computing.

[img]
Preview
PDF
2MB

Official URL: http://dms.library.utm.my:8080/vital/access/manage...

Abstract

The Intrusion Detection System (IDS) is an industrial-driven technology that monitors the network infrastructure of an organization from malicious intent. Although the IDS technology has advanced tremendously, one of the main issues that still remains since its beginning is the huge amount of attack alerts that have to be processed immediately on a daily basis. To manage these alerts effectively, both techniques of data reduction and correlation have to be applied concurrently. Therefore, this research proposes a framework named Intelligent Alert Processing Framework (lAPF) that incorporates both techniques named Alert Reduction Module (ARM) and Alert Correlation Module (ACM) to produce an integrated result. The ARM consists of a new clustering algorithm inspired by the Artificial Immune System (AIS) approach which is the Clonal Selection principle, while the ACM is based on pattern recognition approach. The new clustering algorithm introduces a one-to-one clustering method that first and foremost creates cluster based on a perfect matching criterion and next calculates its vulnerability level. Clusters with 0 vulnerability level will be filtered while other clusters will than proceed to ACM for attack scenario formulation and its successful attack scenario probability. The IAPF was successfully experimented using a standard simulated dataset and a real-time dataset from PRISMA (Pemantauan Rangkaian ICT Sektor Awam). The result of the experiment indicated that ARM achieved accurate clustering output, with zero cluster error within an average of 6.36 seconds processing time and the reduction rate of alerts attained is 95.34%. Meanwhile ACM managed to detect all possible attack scenarios based on the predefined patterns. The proposed framework has reduced the number of alerts, creates attack scenarios and simultaneously produced vulnerability level for each clusters and the correlated successful attack scenario probability.

Item Type:Thesis (PhD)
Additional Information:Thesis (Ph.D (Sains Komputer)) - Universiti Teknologi Malaysia, 2015; Supervisor : Prof. Dr. Norbik Bashah Idris
Uncontrolled Keywords:intrusion detection system (IDS), intelligent alert processing framework (lAPF)
Subjects:Q Science > QA Mathematics > QA75 Electronic computers. Computer science
Divisions:Computing
ID Code:54892
Deposited By: Fazli Masari
Deposited On:02 Jun 2016 01:41
Last Modified:15 Nov 2020 09:26

Repository Staff Only: item control page