全部 标题 作者
关键词 摘要

OALib Journal期刊
ISSN: 2333-9721
费用:99美元

查看量下载量

相关文章

更多...

Intelligent Alert Clustering Model for Network Intrusion Analysis

Keywords: alert clustering , alert correlation , Expectation Maximization , Principal Component Analysis , unsupervised learning.

Full-Text   Cite this paper   Add to My Lib

Abstract:

As security threats change and advance in a drastic way, most ofthe organizations implement multiple Network Intrusion DetectionSystems (NIDSs) to optimize detection and to provide comprehensiveview of intrusion activities. But NIDSs trigger a massive amount ofalerts even for a day and overwhelmed security experts. Thus,automated and intelligent clustering is important to reveal theirstructural correlation by grouping alerts with common attributes. Wepropose a new hybrid clustering model based on Improved UnitRange (IUR), Principal Component Analysis (PCA) andunsupervised learning algorithm (Expectation Maximization) toaggregate similar alerts and to reduce the number of alerts. Wetested against other unsupervised learning algorithms to validate theperformance of the proposed model. Our empirical results showusing DARPA 2000 dataset the proposed model gives better results interms of the clustering accuracy and processing time.

Full-Text

Contact Us

service@oalib.com

QQ:3279437679

WhatsApp +8615387084133