dc.date.accessioned | 2020-12-11T08:38:20Z | |
dc.date.available | 2020-12-11T08:38:20Z | |
dc.date.issued | 2014 | |
dc.identifier.uri | http://repository.kippra.or.ke/handle/123456789/2381 | |
dc.description.abstract | Intrusion detection systems (IDSs) often trigger a huge number of unnecessary alerts. Managing the overwhelming number of alerts, especially from multiple IDS products, is a concern to every security analyst. Analyzing and evaluating these alerts is a difficult task that frustrates the effort of analysts. In fact, true alerts are usually buried under heaps of false alerts. We have identified several research gaps in the existing alert management approaches that need to be addressed, especially when handling alerts from different IDS products. In this work, we present an efficient alert management approach that reduces the unnecessary alerts produced by different IDS products using two main modules: an enhanced alert verification module that validates alerts with vulnerability assessment data; and an enhanced alert aggregator module that reduces redundant alerts and presents them in the form of meta alerts. Finally, we have carried out experiments in our test bed and recorded impressive results in terms of high accuracy and low false positive rate for multiple IDS products. | en |
dc.language.iso | en | en |
dc.publisher | International Journal of Network Management | en |
dc.relation.ispartofseries | Journal Article: 2014 | |
dc.subject | Intrusion detection systems | en |
dc.subject | cybercrime | en |
dc.subject | Cyber security | en |
dc.subject | Networking Organizations | en |
dc.title | An Efficient Approach to Reduce Alerts Generated by Multiple IDS Products | en |
dc.type | Journal Article | en |
dcterms.subject | Networking Intrusions | |
dcterms.subject | Security Breaches | |
ppr.contributor.author | Nguyen, Tu Hoang ; Luo, Liawei & Njogu, Humphrey Waita | |