False positive reduction in intrusion detection system: A survey

Autor: Ahmed M. Manasrah, O. Abouabdalla, Sureswaran Ramadass, Homam El-Taj
Rok vydání: 2009
Zdroj: 2009 2nd IEEE International Conference on Broadband Network & Multimedia Technology.
DOI: 10.1109/icbnmt.2009.5348536
Popis: Since the first intrusion detection system and up to this moment all IDSs had generated thousands and thousands of alerts and most of these alerts are false alerts, which lead the researchers to develop an idea to reduce the rate of the alerts or at least the false alerts of them. One of the ideas was to create correlation methods which cover the problem of dealing with the huge amount of both real alerts as well as false alerts. The techniques used in this area plan to help the analyst party to analyze these alerts to distinguish between alerts generated by real attacks and legal traffic. This paper will highlight the false positive reduction techniques surrounding this area.
Databáze: OpenAIRE