A preliminary two-stage alarm correlation and filtering system using SOM neural network and K-means algorithm

被引:68
作者
Tjhai, Gina C. [1 ]
Furnell, Steven M. [1 ]
Papadaki, Maria [1 ]
Clarke, Nathan L. [1 ]
机构
[1] Univ Plymouth, Ctr Secur Commun & Network Res, Plymouth PL4 8AA, Devon, England
关键词
Intrusion Detection System; False alarm; Self Organising Map (SOM); K-means clustering; Alarm correlation;
D O I
10.1016/j.cose.2010.02.001
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Intrusion Detection Systems (IDSs) play a vital role in the overall security infrastructure. Although the IDS has become an essential part of corporate network infrastructure, the art of detecting intrusion is still far from perfect. A significant problem is that of false alarms, as generating a huge volume of such alarms could render the system inefficient. In this paper, we propose a new method to reduce the number of false alarms. We develop a two-stage classification system using a SOM neural network and K-means algorithm to correlate the related alerts and to further classify the alerts into classes of true and false alarms. Preliminary experiments show that our approach effectively reduces all superfluous and noisy alerts, which often contribute to more than 50% of false alarms generated by a common IDS. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:712 / 723
页数:12
相关论文
共 30 条
[1]  
ALHARBY A, 2005, LECT NOTES COMPUTER, V3531
[2]  
[Anonymous], 2002, Proceedings of the 9th ACM conference on Computer and communications security, CCS'02, DOI DOI 10.1145/586110.586144
[3]  
Caswell B., 2004, SNORT OPEN SOURCE NE
[4]   Alarm reduction and correlation in defence of IP networks [J].
Chyssler, T ;
Nadjm-Tehrani, S ;
Burschka, S ;
Burbeck, K .
THIRTEENTH IEEE INTERNATIONAL WORKSHOPS ON ENABLING TECHNOLOGIES: INFRASTRUCTURE FOR COLLABORATIVE ENTERPRISES, PROCEEDINGS, 2004, :229-234
[5]  
CHYSSLER T, 2004, ALARM REDUCTION CORR
[6]  
*CIS, 2005, SOM TOOLB 2 0
[7]  
Cuppens F, 2002, P IEEE S SECUR PRIV, P202, DOI 10.1109/SECPRI.2002.1004372
[8]  
Dain O., 2001, P 2001 ACM WORKSHOP, P1
[9]  
Debar H., 2001, P 4 INT S REC ADV IN, P85, DOI DOI 10.1007/3-540-45474-8_
[10]  
Flexer A, 1997, ADV NEUR IN, V9, P445