AIDA Framework: Real-Time Correlation and Prediction of Intrusion Detection Alerts

被引:12
|
作者
Husak, Martin [1 ]
Kaspar, Jaroslav [1 ]
机构
[1] Masaryk Univ, Inst Comp Sci, Brno, Czech Republic
关键词
intrusion detection; information sharing; alert correlation; prediction; data mining;
D O I
10.1145/3339252.3340513
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we present AIDA, an analytical framework for processing intrusion detection alerts with a focus on alert correlation and predictive analytics. The framework contains components that filter, aggregate, and correlate the alerts, and predict future security events using the predictive rules distilled from historical records. The components are based on stream processing and use selected features of data mining (namely sequential rule mining) and complex event processing. The framework was deployed as an analytical component of an alert sharing platform, where alerts from intrusion detection systems, honeypots, and other data sources are exchanged among the community of peers. The deployment is briefly described and evaluated to illustrate the capabilities of the framework in practice. Further, the framework may be deployed locally for experimentations over datasets.
引用
收藏
页数:8
相关论文
共 50 条
  • [31] A real-time alert correlation method based on code-books for intrusion detection systems
    Mahdavi, Ehsan
    Fanian, Ali
    Amini, Fatima
    COMPUTERS & SECURITY, 2020, 89
  • [32] LDA-ID: An LDA-Based Framework for Real-Time Network Intrusion Detection
    Weidong Zhou
    Shengwei Lei
    Chunhe Xia
    Tianbo Wang
    China Communications, 2023, 20 (12) : 166 - 181
  • [33] LDA-ID: An LDA-Based Framework for Real-Time Network Intrusion Detection
    Zhou, Weidong
    Lei, Shengwei
    Xia, Chunhe
    Wang, Tianbo
    CHINA COMMUNICATIONS, 2023, 20 (12) : 166 - 181
  • [34] SwiftIDS: Real-time intrusion detection system based on LightGBM and parallel intrusion detection mechanism
    Jin, Dongzi
    Lu, Yiqin
    Qin, Jiancheng
    Cheng, Zhe
    Mao, Zhongshu
    COMPUTERS & SECURITY, 2020, 97
  • [35] Intrusion detection in real-time database systems via time signatures
    Lee, VCS
    Stankovic, JA
    Son, SH
    SIXTH IEEE REAL-TIME TECHNOLOGY AND APPLICATIONS SYMPOSIUM, PROCEEDINGS, 2000, : 124 - 133
  • [36] Temporal Correlation and Probabilistic Prediction Based Face Detection Framework in Real Time Environment
    Mayank, Piyush
    Mukhopadhyay, Sudipta
    4TH INTERNATIONAL CONFERENCE ON INTELLIGENT HUMAN COMPUTER INTERACTION (IHCI 2012), 2012,
  • [37] Real-time IRC Threat Detection Framework
    Shao, Sicong
    Tunc, Cihan
    Satam, Pratik
    Hariri, Salim
    2017 IEEE 2ND INTERNATIONAL WORKSHOPS ON FOUNDATIONS AND APPLICATIONS OF SELF* SYSTEMS (FAS*W), 2017, : 318 - 323
  • [38] A real-time framework for eye detection and tracking
    Hussein O. Hamshari
    Steven S. Beauchemin
    Journal of Real-Time Image Processing, 2011, 6 : 235 - 245
  • [39] A real-time framework for eye detection and tracking
    Hamshari, Hussein O.
    Beauchemin, Steven S.
    JOURNAL OF REAL-TIME IMAGE PROCESSING, 2011, 6 (04) : 235 - 245
  • [40] A Framework for Real-Time Spam Detection in Twitter
    Gupta, Himank
    Jamal, Mohd. Saalim
    Madisetty, Sreekanth
    Desarkar, Maunendra Sankar
    2018 10TH INTERNATIONAL CONFERENCE ON COMMUNICATION SYSTEMS & NETWORKS (COMSNETS), 2018, : 380 - 387