• DocumentCode
    3243672
  • Title

    Using Outlier Detection to Reduce False Positives in Intrusion Detection

  • Author

    Xiao, Fu ; Li, Xie

  • Author_Institution
    State Key Lab. for Novel Software Technol., Nanjing Univ., Nanjing
  • fYear
    2008
  • fDate
    18-21 Oct. 2008
  • Firstpage
    26
  • Lastpage
    33
  • Abstract
    Intrusion detection systems (IDSs) can easily create thousands of alerts per day, up to 99% of which are false positives (i.e. alerts that are triggered incorrectly by benign events). This makes it extremely difficult for managers to analyze and react to attacks. This paper presents a novel method for handling IDS alerts more efficiently. It introduces outlier detection technique into this field, and designs a special outlier detection algorithm for identifying true alerts and reducing false positives. This algorithm uses frequent attribute values mined from historical alerts as the features of false positives, and then filters false alerts by the score calculated based on these features. We also proposed a two-phrase framework, which not only can filter newcome alerts in real time, but also can learn from these alerts and automatically adjust the filtering mechanism to new situations. Moreover our method needs no domain knowledge and little human assistance, so it is more practical than current ways. We have built a prototype implementation of our method. And the experiments on DARPA 2000 and real-world data have proved that this model has high performance.
  • Keywords
    security of data; false positives; frequent attribute values; intrusion detection systems; outlier detection algorithm; Algorithm design and analysis; Delay; Detection algorithms; Event detection; Filtering; Filters; Intrusion detection; Laboratories; Machine learning algorithms; Parallel processing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Network and Parallel Computing, 2008. NPC 2008. IFIP International Conference on
  • Conference_Location
    Shanghai
  • Print_ISBN
    978-0-7695-3354-4
  • Type

    conf

  • DOI
    10.1109/NPC.2008.26
  • Filename
    4663300