DocumentCode :
552907
Title :
Concurrent reduction of false positives and redundant alerts
Author :
Nehinbe, J.O.
Author_Institution :
Univ. of Essex, Colchester, UK
fYear :
2010
fDate :
28-30 June 2010
Firstpage :
318
Lastpage :
323
Abstract :
The concurrent reductions of true and false positives in Intrusion Detection Systems are exploitable avenues for attacks to succeed for a number of reasons. Firstly, intrusion detectors can concurrently generate numerous false positives with true positives. Secondly, intrusion aggregation models that are designed to reduce alerts workload reduce clusters of true and false positives at the same rate because the reduction of alert redundancies is not separated from that of false positives. Consequently, there are growing rate of computer attacks despite the inclusion of network detectors on the networks. Therefore, this paper presents a model to investigate these problems. The model consisted of two cooperative components of clustering rules that respectively eliminated redundancies and false positives. Evaluations with series of synthetic and realistic datasets have demonstrated how network analysts could significantly reduce false positive and redundancies in realistic networks and how to promptly thwart ongoing attacks.
Keywords :
pattern clustering; security of data; alerts workload reduction; clustering rules; computer attacks; concurrent reduction; false positives; intrusion aggregation models; intrusion detection systems; redundant alerts; Detectors; Humans; IP networks; Intrusion detection; Protocols; Redundancy; Silicon;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Society (i-Society), 2010 International Conference on
Conference_Location :
London
Print_ISBN :
978-1-4577-1823-6
Electronic_ISBN :
978-0-9564263-3-8
Type :
conf
Filename :
6018721
Link To Document :
بازگشت