DocumentCode :
2308728
Title :
Reducing false positives through fuzzy alert correlation in collaborative intelligent intrusion detection systems — A review
Author :
Elshoush, Huwaida Tagelsir ; Osman, Izzeldin Mohamed
Author_Institution :
Dept. of Comput. Sci., Univ. of Khartoum, Khartoum, Sudan
fYear :
2010
fDate :
18-23 July 2010
Firstpage :
1
Lastpage :
8
Abstract :
As complete prevention of computer attacks is not possible, intrusion detection systems (IDS) play a very important role in minimizing the damage caused by different computer attacks. There are two intrusion detection methods: namely misuse- and anomaly-based. A collaborative intelligent intrusion detection system (CIIDS) is proposed to include both methods, since it is concluded from recent research that the performance of an individual detection engine is rarely satisfactory. In particular, two main challenges in current collaborative intrusion detection systems (CIDSs) research are highlighted and reviewed: CIDS architectures and alert correlation algorithms. The focus will be on correlation of CIIDS alerts. At the end of the review, the paper suggests fuzzy logic and other AI techniques to be exploited to reduce the rate of false alarms while keeping the detection rate high. In conclusion, the paper highlights opportunities for an integrated solution to large-scale CIIDS.
Keywords :
security of data; collaborative intelligent intrusion detection system; computer attacks; false positives; fuzzy alert correlation; fuzzy logic; Artificial intelligence; Collaboration; Correlation; Detectors; Intrusion detection; Protocols;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Fuzzy Systems (FUZZ), 2010 IEEE International Conference on
Conference_Location :
Barcelona
ISSN :
1098-7584
Print_ISBN :
978-1-4244-6919-2
Type :
conf
DOI :
10.1109/FUZZY.2010.5584418
Filename :
5584418
Link To Document :
بازگشت