Title :
Alert Correlation Using a Novel Clustering Approach
Author :
Mohamed, Ashara Banu ; Idris, Norbik Bashah ; Shanmugum, Bharanidharan
Author_Institution :
Adv. Inf. Sch. (AIS), Univ. Teknol. Malaysia (UTM), Kuala Lumpur, Malaysia
Abstract :
Since the birth of Intrusion Detection System (IDS) technology, the most significant implementation problem is the enormous number of alerts generated by the IDS sensors. Moreover due to this obtrusive predicament, two other problems have emerged which are the difficulty in processing the alerts accurately and also the decrease in performance rate in terms of time and memory capacity while processing these alerts. Thus, based on the specified problems, the purpose of our overall research is to construct a holistic solution that is able to reduce the number of alerts to be processed and at the same time to produce a high quality attack scenarios that are meaningful to the administrators in a timely manner. However for the purpose of this paper we will present our proposed clustering method, architectured solely with the intention of reducing the amount of alerts generated by IDS. The clustering method was tested against a live data from a cyber attack monitoring unit that uses SNORT engine to capture the alerts. The result obtained from the experiment is very promising, the clustering algorithm was able to reduce about 86.9% of the alerts used in the experiment. From the result we are able to highlight the contribution to practitioners in an actual working environment.
Keywords :
pattern clustering; security of data; IDS sensors; IDS technology; SNORT engine; alert correlation; clustering approach; cyber attack monitoring unit; high quality attack; intrusion detection system technology; memory capacity; Clustering algorithms; Clustering methods; Humans; IP networks; Intrusion detection; Sensors; IDS; clustering; hashing technique;
Conference_Titel :
Communication Systems and Network Technologies (CSNT), 2012 International Conference on
Conference_Location :
Rajkot
Print_ISBN :
978-1-4673-1538-8
DOI :
10.1109/CSNT.2012.212