Loading...
Please wait, while we are loading the content...
Similar Documents
Improving the quality of alerts with correlation in intrusion detection summary.
| Content Provider | CiteSeerX |
|---|---|
| Abstract | With the growing deployment of networks and the Internet, the importance of network security has increased. Recently, however, systems that detect intrusions, which are important in security countermeasures, have been unable to provide proper analysis or an effective defense mechanism. Instead, they have overwhelmed human operators with a large volume of intrusion detection alerts. In this paper, we present an alert correlation technique based on causal relationships between alerts. The goal of the proposed technique is not only to group alerts together, but also to represent the correlated alerts in a way that they reflect the corresponding attack scenarios. Keywords: |
| File Format | |
| Access Restriction | Open |
| Subject Keyword | Intrusion Detection Alert Detect Intrusion Network Security Proper Analysis Security Countermeasure Effective Defense Mechanism Large Volume Intrusion Detection Summary Human Operator Corresponding Attack Scenario Correlated Alert Alert Correlation Technique Causal Relationship |
| Content Type | Text |