Using alert cluster to reduce IDS alerts

HW Njogu, L Jiawei - 2010 3rd International Conference on …, 2010 - ieeexplore.ieee.org
Intrusion Detection Systems (IDSs) are known to produce huge volumes of alerts. The
interesting alerts are always mixed with irrelevant, duplicate and non interesting alerts. Huge …

False positive reduction in intrusion detection system: A survey

O Abouabdalla, H El-Taj, A Manasrah… - 2009 2nd IEEE …, 2009 - ieeexplore.ieee.org
Since the first intrusion detection system and up to this moment all IDSs had generated
thousands and thousands of alerts and most of these alerts are false alerts, which lead the …

A comprehensive vulnerability based alert management approach for large networks

HW Njogu, L Jiawei, JN Kiere… - Future Generation …, 2013 - Elsevier
Traditional Intrusion Detection Systems (IDSs) are known for generating large volumes of
alerts despite all the progress made over the last few years. The analysis of a huge number …

False positives reduction via intrusion alert quality framework

NA Bakar, B Belaton… - … held with the 2005 IEEE 7th …, 2005 - ieeexplore.ieee.org
Existing security monitoring sensors such as IDS/IPS, firewalls, filtering routers, and others
often record logs and subsequently generate alerts to warn security analysts of what is …

[PDF][PDF] Intrusion detection system-false positive alert reduction technique

M Kumar, M Hanumanthappa, TVS Kumar - ACEEE Int. J. on Network …, 2011 - Citeseer
Intrusion Detection System (IDS) is the most powerful system that can handle the intrusions
of the computer environments by triggering alerts to make the analysts take actions to stop …

An efficient approach to reduce alerts generated by multiple IDS products

TH Nguyen, J Luo, HW Njogu - International Journal of Network …, 2014 - Wiley Online Library
Intrusion detection systems (IDSs) often trigger a huge number of unnecessary alerts.
Managing the overwhelming number of alerts, especially from multiple IDS products, is a …

A test of intrusion alert filtering based on network information

T Sommestad, U Franke - Security and Communication …, 2015 - Wiley Online Library
Intrusion detection systems continue to be a promising security technology. The arguably
biggest problem with today's intrusion detection systems is the sheer number of alerts they …

[PDF][PDF] A Quality Framework to Improve IDS Performance Through Alert Post-Processing.

AM Riyad, MS Irfan Ahmed… - International Journal of …, 2019 - emeacollege.ac.in
An intrusion detection system is one of the network security tools installed to monitor
suspicious activity in the network and act as a last line of defense. It normally notifies about …

[PDF][PDF] False positive reduction by correlating the intrusion detection system alerts: Investigation study

H El-Taj, O Abouabdalla, A Manasrah - Journal of Communication …, 2010 - academia.edu
Intrusion Detection System (IDS) is the most powerful system that can handle the intrusions
of the computer environments by triggering alerts to make the analysts take actions to stop …

Improvements in the model for interoperability of intrusion detection responses compatible with the IDWG model

PF da Silva, CB Westphall - International Journal of Network …, 2007 - Wiley Online Library
This paper presents a model for response interoperability between intruder detection
systems (IDSs), compatible with the model for alert interoperability developed by the …