• Login
    Advanced Search
    • | About us
    • | eJournals
    • | Feedback
    • | Help Guide
    View Item 
    •   KIPPRA PPR Home
    • 3. KIPPRA Research Publications
    • Journal Articles
    • View Item
    •   KIPPRA PPR Home
    • 3. KIPPRA Research Publications
    • Journal Articles
    • View Item
    JavaScript is disabled for your browser. Some features of this site may not work without it.

    An Efficient Approach to Reduce Alerts Generated by Multiple IDS Products

    Thumbnail
    View/Open
    Full Text (1.562Mb)
    Publication Date
    2014
    Author
    Nguyen, Tu Hoang ; Luo, Liawei & Njogu, Humphrey Waita
    Type
    Journal Article
    Item Usage Stats
    65
    views
    130
    downloads
    Metadata
    Show full item record
    By
    Nguyen, Tu Hoang ; Luo, Liawei & Njogu, Humphrey Waita
    Abstract/Overview

    Intrusion detection systems (IDSs) often trigger a huge number of unnecessary alerts. Managing the overwhelming number of alerts, especially from multiple IDS products, is a concern to every security analyst. Analyzing and evaluating these alerts is a difficult task that frustrates the effort of analysts. In fact, true alerts are usually buried under heaps of false alerts. We have identified several research gaps in the existing alert management approaches that need to be addressed, especially when handling alerts from different IDS products. In this work, we present an efficient alert management approach that reduces the unnecessary alerts produced by different IDS products using two main modules: an enhanced alert verification module that validates alerts with vulnerability assessment data; and an enhanced alert aggregator module that reduces redundant alerts and presents them in the form of meta alerts. Finally, we have carried out experiments in our test bed and recorded impressive results in terms of high accuracy and low false positive rate for multiple IDS products.

    Subject/Keywords
    Intrusion detection systems; cybercrime; Cyber security; Networking Organizations; Networking Intrusions; Security Breaches
    Publisher
    International Journal of Network Management
    Series
    Journal Article: 2014
    Permalink
    http://repository.kippra.or.ke/handle/123456789/2381
    Collections
    • Journal Articles [20]


    Contact Us | Send Feedback
     
    Related Links
    The National Treasury & PlanningKenya National Bureau of StatisticsMaarifa Centre - An Initiative of the Council of Governors (CoG)Kenya Revenue AuthorityParliament of KenyaAfrican Economic Research ConsortiumBrookings Institution

    Browse

    All of KIPPRA PPRCommunities & CollectionsBy Issue DateAuthorsTitlesSubjectsThis CollectionBy Issue DateAuthorsTitlesSubjects

    My Account

    LoginRegister

    Statistics

    View Usage StatisticsView Google Analytics Statistics

    Contact Us | Send Feedback