Alert correlation in a cooperative intrusion detection framework
Office National d'Études et de Recherches Aérospatiales
Abstract
This paper presents the work we have done within the MIRADOR project to design CRIM, a cooperative module for intrusion detection systems (IDS). This module implements functions to manage, cluster, merge and correlate alerts. The clustering and merging functions recognize alerts that correspond to the same occurrence of an attack and create a new alert that merge data contained in these various alerts. Experiments show that these functions significantly reduce the number of alerts. However, we also observe that alerts we obtain are still too elementary to be managed by a security administrator. The purpose of the correlation function is thus to generate global and synthetic alerts. This paper focuses on the…
Citation impact
- FWCI
- 63.51
- Percentile
- 100%
- References
- 15
Authors
2Topics & keywords
- Merge (version control)
- Intrusion detection system
- Computer science
- Cluster analysis
- Data mining
- Intrusion
- Correlation
- Computer security