[PDF][PDF] Intrusion detection system-false positive alert reduction technique

M Kumar, M Hanumanthappa, TVS Kumar - ACEEE Int. J. on Network …, 2011 - Citeseer
ACEEE Int. J. on Network Security, 2011Citeseer
Intrusion Detection System (IDS) is the most powerful system that can handle the intrusions
of the computer environments by triggering alerts to make the analysts take actions to stop
this intrusion, but the IDS is triggering alerts for any suspicious activity which means
thousand alerts that the analysts should take care of it. IDS generate a large number of alerts
and most of them are false positive as the behavior construe for partial attack pattern or lack
of environment knowledge. These Alerts has different severities and most of them don't …
Abstract
Intrusion Detection System (IDS) is the most powerful system that can handle the intrusions of the computer environments by triggering alerts to make the analysts take actions to stop this intrusion, but the IDS is triggering alerts for any suspicious activity which means thousand alerts that the analysts should take care of it. IDS generate a large number of alerts and most of them are false positive as the behavior construe for partial attack pattern or lack of environment knowledge. These Alerts has different severities and most of them don’t require big attention because of the huge number of the false alerts among them. Monitoring and identifying risky alerts is a major concern to security administrator. Deleting the false alerts or reducing the amount of the alerts (false alerts or real alerts) from the entire amount alerts lead the researchers to design an operational model for minimization of false positive alarms, including recurring alarms by security administrator. In this paper we are proposing a method, which can reduce such kind of false positive alarms.
Citeseer
以上显示的是最相近的搜索结果。 查看全部搜索结果