Intrusion detection alert verification based on multi-level fuzzy comprehensive evaluation

Chengpo Mu*, Houkuan Huang, Shengfeng Tian

*Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

20 Citations (Scopus)

Abstract

Alert verification is a process which compares the information referred by an alert with the configuration and topology information of its target system in order to determine if the alert is relevant to its target system. It can reduce false positive alerts and irrelevant alerts. The paper presents an alert verification approach based on multi-level fuzzy comprehensive evaluation. It is effective in achieving false alert and irrelevant alerts reduction, which have been proved by our experiments. The algorithm can deal with the uncertainties better than other alert verification approaches. The relevance score vectors obtained from the algorithm facilitate the formulation of fine and flexible security policies, and further alert processing.

Original languageEnglish
Title of host publicationComputational Intelligence and Security - International Conference, CIS 2005, Proceedings
Pages9-16
Number of pages8
DOIs
Publication statusPublished - 2005
Externally publishedYes
EventInternational Conference on Computational Intelligence and Security, CIS 2005 - Xi'an, China
Duration: 15 Dec 200519 Dec 2005

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume3801 LNAI
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

ConferenceInternational Conference on Computational Intelligence and Security, CIS 2005
Country/TerritoryChina
CityXi'an
Period15/12/0519/12/05

Fingerprint

Dive into the research topics of 'Intrusion detection alert verification based on multi-level fuzzy comprehensive evaluation'. Together they form a unique fingerprint.

Cite this