Approach based on rough set theory in aggregating alerts of cooperative intrusion detection system

Feng Liu*, Changzhen Hu, Yanmin Shuai

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

In this paper three light-weighted detectors have been developed in order to protect the key host. Alerts from each detector have been aggregated and correlated in the spatio-temporal space. Due to the uncertainty in describing attacks, the rough set theory has been applied into the aggregation of alerts in the spatial space. Experiments show that this way can not only reduce the amount of futile and repetitive alerts but also increase the detection rate.

Original languageEnglish
Pages (from-to)27-28+210
JournalJisuanji Gongcheng/Computer Engineering
Volume31
Issue number7
Publication statusPublished - 5 Apr 2005

Keywords

  • Cooperative Intrusion detection system
  • Network security
  • Rough set theory

Fingerprint

Dive into the research topics of 'Approach based on rough set theory in aggregating alerts of cooperative intrusion detection system'. Together they form a unique fingerprint.

Cite this