On the use of different statistical tests for alert correlation: short paper

  • Authors:
  • Federico Maggi;Stefano Zanero

  • Affiliations:
  • Politecnico di Milano, Dip. Elettronica e Informazione, Milano, Italy;Politecnico di Milano, Dip. Elettronica e Informazione, Milano, Italy

  • Venue:
  • RAID'07 Proceedings of the 10th international conference on Recent advances in intrusion detection
  • Year:
  • 2007

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we analyze the use of different types of statistical tests for the correlation of anomaly detection alerts. We show that the Granger Causality Test, one of the few proposals that can be extended to the anomaly detection domain, strongly depends on good choices of a parameter which proves to be both sensitive and difficult to estimate. We propose a different approach based on a set of simpler statistical tests, and we prove that our criteria work well on a simplified correlation task, without requiring complex configuration parameters.