Security alert correlation using growing neural gas

  • Authors:
  • Francisco José Mora-Gimeno;Francisco Maciá-Pérez;Iren Lorenzo-Fonseca;Juan Antonio Gil-Martínez-Abarca;Diego Marcos-Jorquera;Virgilio Gilart-Iglesias

  • Affiliations:
  • Department of Computer Technology, University of Alicante, Alicante, Spain;Department of Computer Technology, University of Alicante, Alicante, Spain;Department of Computer Technology, University of Alicante, Alicante, Spain;Department of Computer Technology, University of Alicante, Alicante, Spain;Department of Computer Technology, University of Alicante, Alicante, Spain;Department of Computer Technology, University of Alicante, Alicante, Spain

  • Venue:
  • CISIS'11 Proceedings of the 4th international conference on Computational intelligence in security for information systems
  • Year:
  • 2011

Quantified Score

Hi-index 0.00

Visualization

Abstract

The use of alert correlation methods in Distributed Intrusion Detection Systems (DIDS) has become an important process to address some of the current problems in this area. However, the efficiency obtained is far from optimal results. This paper presents a novel approach based on the integration of multiple correlation methods by using the neural network Growing Neural Gas (GNG). Moreover, since correlation systems have different detection capabilities, we have modified the learning algorithm to positively weight the best performing systems. The results show the validity of the proposal, both the multiple integration approach using GNG neural network and the weighting based on efficiency.