Skip to main navigation Skip to search Skip to main content

Fusing Security Alerts Improves Cyber-Security: An Alert Normalization Framework for Heterogeneous Devices

  • Songxuan Wei
  • , Yushun Xie
  • , Angxiao Zhao
  • , Xiao Jing*
  • , Cui Luo
  • , Zhaoquan Gu*
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

With the rapid development of network technologies, cyberspace security is facing increasingly complex threats. To detect and respond to the rapidly growing number of network attacks, many security devices are widely adopted. However, a single security device often detects network attacks based on a single algorithm or some pre-defined features, resulting in a large number of false positives and false negatives in the security alerts it generates. Hence, many heterogeneous security devices are normally used; and fusing the alerts from these devices is an effective way to improve the quality of security alerts. As the formats or even the contents of the reported alerts are quite different, it has become a severe problem to fuse these alerts in practice. To address this problem, we propose an alert normalization framework in this paper for multi-source heterogeneous devices, which can convert different alert types reported by heterogeneous devices into a unified attack classification system automatically, making it possible to jointly analyze these alerts. Our framework extracts keywords describing each attack type by calculating the TF-IDF value, and then uses the normalized TF-IDF value as a weight to predict which attack type the alert belongs to. Experiments on 67,957 security alerts obtained from 15 security devices show that our method has good performance and is well interpretable. In addition, it can predict unseen alerts with a high accuracy of 0.65.

Original languageEnglish
Title of host publicationProceedings - 2023 8th International Conference on Data Science in Cyberspace, DSC 2023
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1-7
Number of pages7
ISBN (Electronic)9798350331035
DOIs
StatePublished - 2023
Externally publishedYes
Event8th International Conference on Data Science in Cyberspace, DSC 2023 - Hefei, China
Duration: 18 Aug 202320 Aug 2023

Publication series

NameProceedings - 2023 8th International Conference on Data Science in Cyberspace, DSC 2023

Conference

Conference8th International Conference on Data Science in Cyberspace, DSC 2023
Country/TerritoryChina
CityHefei
Period18/08/2320/08/23

Keywords

  • Security alerts
  • alert aggregation
  • cyber-security
  • intrusion detection system
  • natural language processing

Fingerprint

Dive into the research topics of 'Fusing Security Alerts Improves Cyber-Security: An Alert Normalization Framework for Heterogeneous Devices'. Together they form a unique fingerprint.

Cite this