An event correlation approach based on the combination of IHU and codebook

  • Authors:
  • Qiuhua Zheng;Yuntao Qian

  • Affiliations:
  • Computational Intelligence Research Laboratory, College of Computer Science, Zhejiang University, Hangzhou, Zhejiang Province, P.R. China;Computational Intelligence Research Laboratory, College of Computer Science, Zhejiang University, Hangzhou, Zhejiang Province, P.R. China

  • Venue:
  • CIS'05 Proceedings of the 2005 international conference on Computational Intelligence and Security - Volume Part II
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper proposes a new event correlation technique, which integrates the increment hypothesis updating (IHU) technique with the codebook approach. The technique allows multiple simultaneous independent faults to be identified when the system’s codebook only includes the codes of the single fault and lacks the information of prior fault probability and the conditional probability of fault lead to symptoms occur. The method utilizes the refined IHU technique to create and update fault hypotheses that can explain these events, and ranks these hypotheses by the codebook approach. The result of event correlation is the hypothesis with maximum hamming distance to the code of the received events. Simulation shows that this approach can get a high accuracy and a fast speed of correlation even if the network has event loss and spuriousness.