@inproceedings{a82a78f8cea6489d90a80801783d0fdd,
title = "Hierarchical distributed alert correlation model",
abstract = "Alert correlation is a promising technique in intrusion detection. It takes the alerts produced by intrusion detection systems and produces compact reports which provide a more succinct and high-level view of occurring or attempted intrusions and highly improve security expert's work efficiency. Traditional alert correlation system adopts a centralized architecture which can be easily over flooded by the raw alarms. To address this issue, a distributed alert correlation model based on hierarchical architecture is proposed. This model greatly improves the performance of alert correlation through integrating three novel methods. The experiments show effectiveness of this alert correlation model on 2000 DARPA intrusion detection scenario specific datasets.",
keywords = "Distributed alert correlation, Hierarchical model, Intrusion detection",
author = "Donghai Tian and Hu Changzhen and Yang Qi and Wang Jianqiao",
year = "2009",
doi = "10.1109/IAS.2009.26",
language = "English",
isbn = "9780769537443",
series = "5th International Conference on Information Assurance and Security, IAS 2009",
publisher = "IEEE Computer Society",
pages = "766--769",
booktitle = "5th International Conference on Information Assurance and Security, IAS 2009",
address = "United States",
note = "5th International Conference on Information Assurance and Security, IAS 2009 ; Conference date: 18-08-2009 Through 20-09-2009",
}