Survey of intrusion-detection alert aggregation and correlation techniques

Chengpo Mu*, Houkuan Huang, Shengfeng Tian

*Corresponding author for this work

Research output: Contribution to journalReview articlepeer-review

26 Citations (Scopus)

Abstract

The significances and goals of alert aggregation and correlation techniques are surveyed comprehensively in this paper. Algorithms of aggregation and correlation and their features are discussed in detail. Meanwhile, the ideas of choosing algorithms in developing the intrusion detection alert manage system are summarized, (IDAMS) are presented. The architectures of all the existing aggregation and correlation systems, with emphasis on a brief introduction of the function of the intrusion detection message exchange format (IDMEF) on alert aggregation and correlation. Finally, the future development of this research domain is presented.

Original languageEnglish
Pages (from-to)1-8
Number of pages8
JournalJisuanji Yanjiu yu Fazhan/Computer Research and Development
Volume43
Issue number1
DOIs
Publication statusPublished - Jan 2006
Externally publishedYes

Keywords

  • Alert aggregation
  • Alert correlation
  • Intrusion detection
  • Network security

Fingerprint

Dive into the research topics of 'Survey of intrusion-detection alert aggregation and correlation techniques'. Together they form a unique fingerprint.

Cite this