Real-time Alert Correlation Using Stream Data Mining Techniques.

IAAI'08 Proceedings of the 20th national conference on Innovative applications of artificial intelligence - Volume 3(2008)

引用 4|浏览0
暂无评分
摘要
With the large volume of alerts produced by low-level detectors, management of intrusion alerts is becoming more challenging. Alert Correlation addresses this issue by providing a condensed, yet more useful view of the network from the intrusion standpoint. In this paper, we propose a new framework for real-time alert correlation that incorporates novel techniques for aggregating alerts into structured patterns and incremental mining of frequent structured patterns. In the proposed framework, time-sensitive statistical relationships between alerts are maintained in an efficient data structure and are updated incrementally to reflect the latest trends of patterns. The results of experiments with synthetic and real-world datasets demonstrate the efficiency of the proposed techniques. Our Frequent Structure Mining algorithm scales linearly with the size of the dataset and the proposed framework can cope with the throughput of a large-scale network. The ability to answer time-sensitive queries about patterns is another advantage of this work compared to other methods.
更多
查看译文
关键词
proposed framework,new framework,proposed technique,frequent structured pattern,intrusion standpoint,large-scale network,structured pattern,time-sensitive query,time-sensitive statistical relationship,Alert Correlation,real-time alert correlation,stream data mining technique
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要