An IDS Alerts Aggregation Algorithm Based on Rough Set Theory

被引:2
|
作者
Zhang, Ru [1 ]
Guo, Tao [1 ]
Liu, Jianyi [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Sch Cyberspace Secur, Beijing, Peoples R China
关键词
NUMBER;
D O I
10.1088/1757-899X/322/6/062009
中图分类号
TE [石油、天然气工业]; TK [能源与动力工程];
学科分类号
0807 ; 0820 ;
摘要
Within a system in which has been deployed several IDS, a great number of alerts can be triggered by a single security event, making real alerts harder to be found. To deal with redundant alerts, we propose a scheme based on rough set theory. In combination with basic concepts in rough set theory, the importance of attributes in alerts was calculated firstly. With the result of attributes importance, we could compute the similarity of two alerts, which will be compared with a pre-defined threshold to determine whether these two alerts can be aggregated or not. Also, time interval should be taken into consideration. Allowed time interval for different types of alerts is computed individually, since different types of alerts may have different time gap between two alerts. In the end of this paper, we apply proposed scheme on DAPRA98 dataset and the results of experiment show that our scheme can efficiently reduce the redundancy of alerts so that administrators of security system could avoid wasting time on useless alerts.
引用
收藏
页数:7
相关论文
共 50 条
  • [31] The fault diagnosis algorithm for transformer based on Extenics and rough set theory
    Shu Hong-chun
    Hu Ze-jiang
    Sun Shi-yun
    Yang Qing
    [J]. 2008 THIRD INTERNATIONAL CONFERENCE ON ELECTRIC UTILITY DEREGULATION AND RESTRUCTURING AND POWER TECHNOLOGIES, VOLS 1-6, 2008, : 1269 - 1272
  • [32] An Efficient Gene Selection Algorithm Based on Tolerance Rough Set Theory
    Na Jiao
    Miao, Duoqian
    [J]. ROUGH SETS, FUZZY SETS, DATA MINING AND GRANULAR COMPUTING, PROCEEDINGS, 2009, 5908 : 176 - +
  • [33] Half-global discretization algorithm based on rough set theory
    Tan Xu & Chen Yingwu School of Information Systems & Management
    [J]. Journal of Systems Engineering and Electronics, 2009, 20 (02) : 339 - 347
  • [34] Selection of Suppliers Based on Rough Set Theory and Fuzzy TOPSIS Algorithm
    Fan, Zhiping
    Hong, Tiansheng
    Liu, Zhizhuang
    [J]. 2008 IEEE INTERNATIONAL SYMPOSIUM ON KNOWLEDGE ACQUISITION AND MODELING WORKSHOP PROCEEDINGS, VOLS 1 AND 2, 2008, : 979 - +
  • [35] A Stream Clustering Algorithm for Classifying Network IDS Alerts
    Vaarandi, Risto
    [J]. PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2021, : 14 - 19
  • [36] Formal Concept Analysis Based on Rough Set Theory and a Construction Algorithm of Rough Concept Lattice
    Yang, Haifeng
    [J]. EMERGING RESEARCH IN ARTIFICIAL INTELLIGENCE AND COMPUTATIONAL INTELLIGENCE, 2011, 237 : 239 - 244
  • [37] An clustering algorithm based on rough set
    Xu, E.
    Gao Xuedong
    Sen, Wu
    Bin, Yu
    [J]. 2006 3RD INTERNATIONAL IEEE CONFERENCE INTELLIGENT SYSTEMS, VOLS 1 AND 2, 2006, : 466 - 469
  • [38] Aggregation of Similarity Measures for Ortholog Detection: Validation with Measures Based on Rough Set Theory
    Millo Sanchez, Reinier
    Galpert Canizares, Deborah
    Casa Cardoso, Gladys
    Grau Abalo, Ricardo
    Arco Garcia, Leticia
    Garcia Lorenzo, Maria Matilde
    Fernandez Marin, Miguel Angel
    [J]. COMPUTACION Y SISTEMAS, 2014, 18 (01): : 19 - 35
  • [39] A novel attribute reduction algorithm based on rough set and information entropy theory
    Wang, Baoyi
    Zhang, Shaomin
    [J]. CIS WORKSHOPS 2007: INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY WORKSHOPS, 2007, : 81 - +
  • [40] Robot path planning method based on rough set theory and a genetic algorithm
    Wang, Ying
    Liu, Qi
    [J]. AGRO FOOD INDUSTRY HI-TECH, 2017, 28 (01): : 1972 - 1976