Mining Alarm Clusters to Improve Alarm Handling Efficiency

  • Authors:
  • K. Julisch

  • Affiliations:
  • -

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

It is a well-known problem that intrusion detection systemsoverload their human operators by triggering thousandsof alarms per day. As a matter of fact, we havebeen asked by one of our service divisions to help themdeal with this problem. This paper presents the results ofour research, validated thanks to a large set of operationaldata. We show that alarms should be managed by identifyingand resolving their root causes. Alarm clustering isintroduced as a method that supports the discovery of rootcauses. The general alarm clustering problem is proved tobe NP-complete, an approximation algorithm is proposed,and experiments are presented.