Hierarchical distributed alert correlation model

Donghai Tian*, Hu Changzhen, Yang Qi, Wang Jianqiao

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

12 Citations (Scopus)

Abstract

Alert correlation is a promising technique in intrusion detection. It takes the alerts produced by intrusion detection systems and produces compact reports which provide a more succinct and high-level view of occurring or attempted intrusions and highly improve security expert's work efficiency. Traditional alert correlation system adopts a centralized architecture which can be easily over flooded by the raw alarms. To address this issue, a distributed alert correlation model based on hierarchical architecture is proposed. This model greatly improves the performance of alert correlation through integrating three novel methods. The experiments show effectiveness of this alert correlation model on 2000 DARPA intrusion detection scenario specific datasets.

Original languageEnglish
Title of host publication5th International Conference on Information Assurance and Security, IAS 2009
PublisherIEEE Computer Society
Pages766-769
Number of pages4
ISBN (Print)9780769537443
DOIs
Publication statusPublished - 2009
Event5th International Conference on Information Assurance and Security, IAS 2009 - Xian, China
Duration: 18 Aug 200920 Sept 2009

Publication series

Name5th International Conference on Information Assurance and Security, IAS 2009
Volume2

Conference

Conference5th International Conference on Information Assurance and Security, IAS 2009
Country/TerritoryChina
CityXian
Period18/08/0920/09/09

Keywords

  • Distributed alert correlation
  • Hierarchical model
  • Intrusion detection

Fingerprint

Dive into the research topics of 'Hierarchical distributed alert correlation model'. Together they form a unique fingerprint.

Cite this