Alert correlation survey: framework and techniques

  • Authors:
  • Reza Sadoddin;Ali Ghorbani

  • Affiliations:
  • University of New Brunswick, Fredericton, New Brunswick, Canada;University of New Brunswick, Fredericton, New Brunswick, Canada

  • Venue:
  • Proceedings of the 2006 International Conference on Privacy, Security and Trust: Bridge the Gap Between PST Technologies and Business Services
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Managing raw alerts generated by various sensors are becoming of more significance to intrusion detection systems as more sensors with different capabilities are distributed spatially in the network. Alert Correlation addresses this issue by reducing, fusing and correlating raw alerts to provide a condensed, yet more meaningful view of the network from the intrusion standpoint. Techniques from a divers range of disciplines have been used by researchers for different aspects of correlation. This paper provides a survey of the state of the art in alert correlation techniques. Our main contribution is a two-fold classification of literature based on correlation framework and applied techniques. The previous works in each category have been described alongside with their strengths and weaknesses from our viewpoint.