Time series modeling for IDS alert management

  • Authors:
  • Jouni Viinikka;Hervé Debar;Ludovic Mé;Renaud Séguier

  • Affiliations:
  • France Telecom, BP, Caen Cedex, France;France Telecom, BP, Caen Cedex, France;Supélec, BP, Cesson Sévigné Cedex, France;Supélec, BP, Cesson Sévigné Cedex, France

  • Venue:
  • ASIACCS '06 Proceedings of the 2006 ACM Symposium on Information, computer and communications security
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Intrusion detection systems create large amounts of alerts. Significant part of these alerts can be seen as background noise of an operational information system, and its quantity typically overwhelms the user. In this paper we have three points to make. First, we present our findings regarding the causes of this noise. Second, we provide some reasoning why one would like to keep an eye on the noise despite the large number of alerts. Finally, one approach for monitoring the noise with reasonable user load is proposed. The approach is based on modeling regularities in alert flows with classical time series methods. We present experimentations and results obtained using real world data.