Hierarchical Distributed Alert Correlation Model

  • Authors:
  • Donghai Tian;Hu Changzhen;Yang Qi;Wang Jianqiao

  • Affiliations:
  • -;-;-;-

  • Venue:
  • IAS '09 Proceedings of the 2009 Fifth International Conference on Information Assurance and Security - Volume 02
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Alert correlation is a promising technique in intrusion detection. It takes the alerts produced by intrusion detection systems and produces compact reports which provide a more succinct and high-level view of occurring or attempted intrusions and highly improve security expert’s work efficiency. Traditional alert correlation system adopts a centralized architecture which can be easily over flooded by the raw alarms. To address this issue, a distributed alert correlation model based on hierarchical architecture is proposed. This model greatly improves the performance of alert correlation through integrating three novel methods. The experiments show effectiveness of this alert correlation model on 2000 DARPA intrusion detection scenario specific datasets.