DocumentCode
552907
Title
Concurrent reduction of false positives and redundant alerts
Author
Nehinbe, J.O.
Author_Institution
Univ. of Essex, Colchester, UK
fYear
2010
fDate
28-30 June 2010
Firstpage
318
Lastpage
323
Abstract
The concurrent reductions of true and false positives in Intrusion Detection Systems are exploitable avenues for attacks to succeed for a number of reasons. Firstly, intrusion detectors can concurrently generate numerous false positives with true positives. Secondly, intrusion aggregation models that are designed to reduce alerts workload reduce clusters of true and false positives at the same rate because the reduction of alert redundancies is not separated from that of false positives. Consequently, there are growing rate of computer attacks despite the inclusion of network detectors on the networks. Therefore, this paper presents a model to investigate these problems. The model consisted of two cooperative components of clustering rules that respectively eliminated redundancies and false positives. Evaluations with series of synthetic and realistic datasets have demonstrated how network analysts could significantly reduce false positive and redundancies in realistic networks and how to promptly thwart ongoing attacks.
Keywords
pattern clustering; security of data; alerts workload reduction; clustering rules; computer attacks; concurrent reduction; false positives; intrusion aggregation models; intrusion detection systems; redundant alerts; Detectors; Humans; IP networks; Intrusion detection; Protocols; Redundancy; Silicon;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Society (i-Society), 2010 International Conference on
Conference_Location
London
Print_ISBN
978-1-4577-1823-6
Electronic_ISBN
978-0-9564263-3-8
Type
conf
Filename
6018721
Link To Document