期刊论文详细信息
International Journal of Computer Science and Security
Managing Intrusion Detection Alerts Using Support Vector Machines
Minoo Deljavan Anvary1  Omid Sojoodi1  Majid Ghonji Feshki1 
[1] $$
关键词: Intrusion Detection System;    Alert Management;    Support Vector Machine;    Security Alert Classification;    Reduction of False Positive Alerts;    Classifying True Positive Alert Based on Their Attack types.;   
DOI  :  
来源: Computer Science and Security
PDF
【 摘 要 】

In the computer network world Intrusion detection systems (IDS) are used to identify attacks against computer systems. They produce security alerts when an attack is done by an intruder. Since IDSs generate high amount of security alerts, analyzing them are time consuming and error prone. To solve this problem IDS alert management techniques are introduced. They manage generated alerts and handle true positive and false positive alerts. In this paper a new alert management system is presented. It uses support vector machine (SVM) as a core component of the system that classify generated alerts. The proposed algorithm achieves high accurate result in false positives reduction and identifying type of true positives. Because of low classification time per each alert, the system also could be used in active alert management systems.

【 授权许可】

Unknown   

【 预 览 】
附件列表
Files Size Format View
RO201912040511588ZK.pdf 119KB PDF download
  文献评价指标  
  下载次数:18次 浏览次数:14次