• DocumentCode
    552907
  • Title

    Concurrent reduction of false positives and redundant alerts

  • Author

    Nehinbe, J.O.

  • Author_Institution
    Univ. of Essex, Colchester, UK
  • fYear
    2010
  • fDate
    28-30 June 2010
  • Firstpage
    318
  • Lastpage
    323
  • Abstract
    The concurrent reductions of true and false positives in Intrusion Detection Systems are exploitable avenues for attacks to succeed for a number of reasons. Firstly, intrusion detectors can concurrently generate numerous false positives with true positives. Secondly, intrusion aggregation models that are designed to reduce alerts workload reduce clusters of true and false positives at the same rate because the reduction of alert redundancies is not separated from that of false positives. Consequently, there are growing rate of computer attacks despite the inclusion of network detectors on the networks. Therefore, this paper presents a model to investigate these problems. The model consisted of two cooperative components of clustering rules that respectively eliminated redundancies and false positives. Evaluations with series of synthetic and realistic datasets have demonstrated how network analysts could significantly reduce false positive and redundancies in realistic networks and how to promptly thwart ongoing attacks.
  • Keywords
    pattern clustering; security of data; alerts workload reduction; clustering rules; computer attacks; concurrent reduction; false positives; intrusion aggregation models; intrusion detection systems; redundant alerts; Detectors; Humans; IP networks; Intrusion detection; Protocols; Redundancy; Silicon;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Society (i-Society), 2010 International Conference on
  • Conference_Location
    London
  • Print_ISBN
    978-1-4577-1823-6
  • Electronic_ISBN
    978-0-9564263-3-8
  • Type

    conf

  • Filename
    6018721