articleAug 24, 2005Closed access

Alert correlation in a cooperative intrusion detection framework

Office National d'Études et de Recherches Aérospatiales

Indexed incrossref

Abstract

This paper presents the work we have done within the MIRADOR project to design CRIM, a cooperative module for intrusion detection systems (IDS). This module implements functions to manage, cluster, merge and correlate alerts. The clustering and merging functions recognize alerts that correspond to the same occurrence of an attack and create a new alert that merge data contained in these various alerts. Experiments show that these functions significantly reduce the number of alerts. However, we also observe that alerts we obtain are still too elementary to be managed by a security administrator. The purpose of the correlation function is thus to generate global and synthetic alerts. This paper focuses on the…

Citation impact

689
total citations
FWCI
63.51
Percentile
100%
References
15
Citations per year

Authors

2

Topics & keywords

Keywords
  • Merge (version control)
  • Intrusion detection system
  • Computer science
  • Cluster analysis
  • Data mining
  • Intrusion
  • Correlation
  • Computer security
No related works found for this paper.

Funding