An IDS Alerts Aggregation Algorithm Based on Rough Set Theory

被引:2
|
作者
Zhang, Ru [1 ]
Guo, Tao [1 ]
Liu, Jianyi [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing, Peoples R China
关键词
NUMBER;
D O I
10.1088/1757-899X/322/6/062009
中图分类号
TE [石油、天然气工业]; TK [能源与动力工程];
学科分类号
0807 ; 0820 ;
摘要
Within a system in which has been deployed several IDS, a great number of alerts can be triggered by a single security event, making real alerts harder to be found. To deal with redundant alerts, we propose a scheme based on rough set theory. In combination with basic concepts in rough set theory, the importance of attributes in alerts was calculated firstly. With the result of attributes importance, we could compute the similarity of two alerts, which will be compared with a pre-defined threshold to determine whether these two alerts can be aggregated or not. Also, time interval should be taken into consideration. Allowed time interval for different types of alerts is computed individually, since different types of alerts may have different time gap between two alerts. In the end of this paper, we apply proposed scheme on DAPRA98 dataset and the results of experiment show that our scheme can efficiently reduce the redundancy of alerts so that administrators of security system could avoid wasting time on useless alerts.
引用
收藏
页数:7
相关论文
共 50 条
  • [1] An SR-ISODATA Algorithm for IDS Alerts Aggregation
    Long, Chun
    Shen, Hanji
    Li, Jun
    Ge, Jingguo
    [J]. 2014 IEEE INTERNATIONAL CONFERENCE ON INFORMATION AND AUTOMATION (ICIA), 2014, : 92 - 97
  • [2] A Rough Set Based Alerts Aggregation and Correlation Model for Intrusion Detection
    Zhou, Lin
    Wang, Chunping
    Jiang, Feng
    [J]. 2012 THIRD INTERNATIONAL CONFERENCE ON TELECOMMUNICATION AND INFORMATION (TEIN 2012), 2012, : 27 - 33
  • [3] Approximate Reduction Algorithm Based on Rough Set Theory
    Shao Bin
    Jiang Yunhang
    Shen Qing
    [J]. PROCEEDINGS OF THE 2008 INTERNATIONAL CONFERENCE ON CYBERWORLDS, 2008, : 410 - 415
  • [4] An incremental learning algorithm based on rough set theory
    Ma, Yinghong
    Han, Yehong
    [J]. COMPUTATIONAL SCIENCE - ICCS 2007, PT 3, PROCEEDINGS, 2007, 4489 : 444 - +
  • [5] An Improved DM Algorithm Based on Rough Set Theory
    Yang Zu-Qiao
    Xiao Xiao-Hong
    Gao Han-ping
    [J]. 2007 INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-15, 2007, : 3097 - 3100
  • [6] An Improved Algorithm for CART based on the Rough Set Theory
    Wang, Weiguang
    Wang, Cong
    Gao, Wanlin
    Li, Jinbin
    [J]. 2013 FOURTH GLOBAL CONGRESS ON INTELLIGENT SYSTEMS (GCIS), 2013, : 11 - 15
  • [7] A data mining algorithm based on rough set theory
    Zhou, CL
    Li, ZG
    Meng, YJ
    Meng, QL
    [J]. ICIA 2004: Proceedings of 2004 International Conference on Information Acquisition, 2004, : 413 - 416
  • [8] An Algorithm for Clustering Data Based on Rough Set Theory
    Wu, Shangzhi
    [J]. ISISE 2008: INTERNATIONAL SYMPOSIUM ON INFORMATION SCIENCE AND ENGINEERING, VOL 2, 2008, : 433 - 436
  • [9] Classification of digital mammography algorithm based on rough set theory
    Hassanien, AE
    Ali, JMH
    [J]. AUTOMATIC CONTROL AND COMPUTER SCIENCES, 2003, 37 (06) : 64 - 71
  • [10] Rough set theory in discretization method based on genetic algorithm
    Huang, Lei
    [J]. PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON MECHATRONICS, MATERIALS, CHEMISTRY AND COMPUTER ENGINEERING 2015 (ICMMCCE 2015), 2015, 39 : 2089 - 2092