An agent-based framework for intrusion detection alert verification and event correlation

  • Authors:
  • Benjamin Uphoff;Johnny S. Wong

  • Affiliations:
  • Los Alamos National Laboratory, Los Alamos, NM, USA.;Department of Computer Science, Iowa State University, Ames, Iowa, USA

  • Venue:
  • International Journal of Security and Networks
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper, we present a framework design and implementation that provides a scalable solution for two important components of alert correlation: alert verification and event correlation. In our framework, a broker application maintains a database containing IDS alerts while software agents perform alert verification and event correlation of alert instances. Agents are designed to run on multiple hosts to ensure scalability of complex tasks. Agents communicate with the broker via web service architecture, making them easy to build and deploy in heterogeneous networks. Three IDSs are supported to show that the framework can be applied to differing IDS paradigms.