The overwhelming number of alarms generated by rule-based network intrusion detection systems makes the task of network security operators ineffective. Preliminary results on an approach called EXOLAP shows that false positive alarms can be avoided by detecting changes on the stream of alarms using a data cube and median polish procedure. A data cube aggregates alarms by hierarchical time frames, rule number, target port number and other feature attributes. The median polish procedure is used on materialized relational views of the data cube to detect changes on the stream of alarms. EXOLAP shows promising results on labeled and unlabeled test sets by focusing on exceptions on the normal stream of alarms, diverting the attention away from false positives. © Springer-Verlag Berlin Heidelberg 2004.
CITATION STYLE
Levera, J., Barán, B., & Grossman, R. (2004). Experimental studies using median polish procedure to reduce alarm rates in data cubes of intrusion data. Lecture Notes in Computer Science (Including Subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 3073, 457–466. https://doi.org/10.1007/978-3-540-25952-7_36
Mendeley helps you to discover research relevant for your work.