• DocumentCode
    2434046
  • Title

    An Alert Correlation Method Based on Improved Cluster Algorithm

  • Author

    Peng, Xi ; Zhang, Yugang ; Xiao, Shisong ; Wu, Zheng ; Cui, Jianqun ; Chen, Limiao ; Xiao, Debao

  • Author_Institution
    Dept. of Comput. Sci., Huazhong Normal Univ., Wuhan
  • Volume
    1
  • fYear
    2008
  • fDate
    19-20 Dec. 2008
  • Firstpage
    342
  • Lastpage
    347
  • Abstract
    In the past several years, the alert correlation methods have been advocated to discover high-level attack scenarios by correlating the low-level alerts. The causal correlation method based on prerequisites and consequences has great advantages in the process of correlating alerts. But it must depend on complicated background knowledge base and has some limits in discovering new attacks. The cluster can aggregate the relational alerts by computing the similarity between alert attributes, as well as can discover new and simple high-level attacks. However, it is difficult to establish the attribute weights in the similarity membership function of two alerts and the threshold of classification similarity value. In order to solve the problem, the quantum-behaved particle swarm optimization algorithm is used to optimize the weights and similarity value. In view of the advantages and disadvantages of cluster and correlation, this paper uses improved cluster algorithm to optimize correlation in the process of attack detection. The experimental results on LLS DDoS1.0 prove that the method proposed is useful and effective.
  • Keywords
    particle swarm optimisation; pattern clustering; security of data; LLS DDoS1.0; alert correlation method; attack detection; cluster algorithm; quantum-behaved particle swarm optimization algorithm; similarity membership function; Application software; Clustering algorithms; Collaboration; Computational intelligence; Computer industry; Computer science; Conferences; Correlation; Intrusion detection; Particle swarm optimization; Alert; Cluster; Correlation; QPSO;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computational Intelligence and Industrial Application, 2008. PACIIA '08. Pacific-Asia Workshop on
  • Conference_Location
    Wuhan
  • Print_ISBN
    978-0-7695-3490-9
  • Type

    conf

  • DOI
    10.1109/PACIIA.2008.285
  • Filename
    4756579