Enhanced alert correlation framework for heterogeneous log

4Citations
Citations of this article
5Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Management of intrusion alarms particularly in identifying malware attack is becoming more demanding due to large amount of alert produced by low-level detectors. Alert correlation can provide high-level view of intrusion alerts but incapable of handling large amount of alarm. This paper proposes an enhanced Alert Correlation Framework for sensors and heterogeneous log. It can reduce the large amount of false alarm and identify the perspective of the attack. This framework is mainly focusing on the alert correlation module which consists of Alarm Thread Reconstruction, Log Thread Reconstruction, Attack Session Reconstruction, Alarm Merging and Attack Pattern Identification module. It is evaluated using metric for effectiveness that shows high correlation rate, reduction rate, identification rate and low misclassification rate. Meanwhile in statistical validation it has highly significance result with p < 0.05. This enhanced Alert Correlation Framework can be extended into research areas in alert correlation and computer forensic investigation. © 2011 Springer-Verlag.

Cite

CITATION STYLE

APA

Yusof, R., Selamat, S. R., Sahib, S., Mas’ud, M. Z., & Abdollah, M. F. (2011). Enhanced alert correlation framework for heterogeneous log. In Communications in Computer and Information Science (Vol. 251 CCIS, pp. 107–122). https://doi.org/10.1007/978-3-642-25327-0_10

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free