您当前所在位置: 首页 > 学者

董晓梅

  • 30浏览

  • 0点赞

  • 0收藏

  • 0分享

  • 275下载

  • 0评论

  • 引用

期刊论文

Correlating Alerts with a Data Mining Based Approach

董晓梅Guang Xiang Xiaomei Dong Ge Yu

,-0001,():

URL:

摘要/描述

In monitoring anomalous network activities, intrusion detection systems tend to generate a large amount of alerts, which greatly increase the workload of post-detection analysis and decision-making. In this paper, we propose a correlation approach based on sequential pattern mining techniques to fuse related alerts for the Distributed Denial of Service (DDoS) attacks. By mining the alert sequences and iteratively consolidating the matching sequential alert patterns, our approach is able to greatly reduce the related alerts and identify their DDoS membership. The alert reduction and fusing mechanism allow us to concentrate on a higher level of abstraction and thus save much extra efforts spent on analyzing a big volume of trivial raw alerts. Experimental comparisons of our method with hidden Markov model (HMM), a powerful stochastic process for sequence analysis, show that our algorithm is slightly better than HMM in terms of DDoS alert sequence identification.

关键词:

【免责声明】以下全部内容由[董晓梅]上传于[2007年10月22日 10时42分48秒],版权归原创者所有。本文仅代表作者本人观点,与本网站无关。本网站对文中陈述、观点判断保持中立,不对所包含内容的准确性、可靠性或完整性提供任何明示或暗示的保证。请读者仅作参考,并请自行承担全部责任。

我要评论

全部评论 0

本学者其他成果

    同领域成果