Skip to main navigation Skip to search Skip to main content

An adaptive alert correlation method based on pattern mining and clustering analysis

  • Zhihong Tian*
  • , Yongzheng Zhang
  • , Weizhe Zhang
  • , Yang Li
  • , Jianwei Ye
  • *Corresponding author for this work
  • School of Computer Science and Technology, Harbin Institute of Technology
  • CAS - Institute of Computing Technology
  • Research Institution of China Mobile

Research output: Contribution to journalArticlepeer-review

Abstract

Multi-step attack is one of the primary forms of the current attacks. There are some relationships among each step of attacks, such as redundancy relationship and causality relationship. But the relationships among security events are often ignored by the current intrusion detection systems (IDS), and an important problem in the field of IDS is a large volume of false positive which tends to overwhelm human operators. On the basis of analyzing the evolution and drawbacks of current alert correlation systems, a self-adapted alarming association method, A3PC, is presented based on anomaly detection ideas and centering on the concept of behavior patterns generated by alerts. The alert classification model is created by extracting association rules and series patterns in order to automatically discriminate the false alerts. At the same time, effective and condensed alerts view for administrators can be shaped based on the combinative idea of pattern mining and clustering analysis and the semiautomatic interactive processing approach. The accuracy of intrusion detection systems is thus enhanced. The DARPA intrusion scenario dataset from MIT Lincoln Lab is used to evaluate the function and performance of A3PC. The experiments results indicate that A3PC is superior to the traditional methods in accuracy, real-time and adaptivity.

Original languageEnglish
Pages (from-to)1304-1315
Number of pages12
JournalJisuanji Yanjiu yu Fazhan/Computer Research and Development
Volume46
Issue number8
StatePublished - Aug 2009
Externally publishedYes

Keywords

  • Alert correlation
  • Clustering analysis
  • False positive
  • Intrusion detection
  • Pattern mining

Fingerprint

Dive into the research topics of 'An adaptive alert correlation method based on pattern mining and clustering analysis'. Together they form a unique fingerprint.

Cite this