• DocumentCode
    3280737
  • Title

    Alert correlation framework using a novel clustering approach

  • Author

    Mohamed, Ashara Banu ; Idris, Norbik Bashah ; Shanmugum, Bharanidharan

  • Author_Institution
    Adv. Inf. Sch. (AIS), Univ. Teknol. Malaysia (UTM), Kuala Lumpur, Malaysia
  • Volume
    1
  • fYear
    2012
  • fDate
    12-14 June 2012
  • Firstpage
    403
  • Lastpage
    408
  • Abstract
    Currently, the primary and pressing issue in IDS implementation is the enormous number of alerts generated by the IDS sensors. Moreover, due to this obtrusive predicament, two other problems have emerged, first is the difficulty in processing the alerts accurately and second is the reduction in performance rate in terms of time and memory capacity while processing these alerts. The purpose of this research is to construct a holistic solution that is able to firstly reduce the number of alerts to be processed and at the same time produce a high quality attack scenarios that are meaningful to the administrators in a timely manner. To achieve these goals, alerts generated by IDS sensors need to be correlated and organized in an appropriate approach. Thus the significant contribution of this research is to create an integrated operational framework for alert processing that reduces the amount of alerts to be processed and creates more meaningful attack scenarios to be analyzed. We are presenting the results obtained from the clustering algorithm and discuss its significant contribution to practitioners in an actual working environment.
  • Keywords
    correlation theory; cryptography; pattern clustering; sensors; storage management; IDS implementation; IDS sensors; alert correlation framework; alert processing; clustering approach; high quality attack scenarios; ideographic description sequence; integrated operational framework; memory capacity; obtrusive predicament; performance rate reduction; time capacity; Engines; IP networks; Probes; IDS; clustering; hashing technique;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer & Information Science (ICCIS), 2012 International Conference on
  • Conference_Location
    Kuala Lumpeu
  • Print_ISBN
    978-1-4673-1937-9
  • Type

    conf

  • DOI
    10.1109/ICCISci.2012.6297279
  • Filename
    6297279