Matches in SemOpenAlex for { <https://semopenalex.org/work/W2090638693> ?p ?o ?g. }
- W2090638693 endingPage "430" @default.
- W2090638693 startingPage "419" @default.
- W2090638693 abstract "As soon as the Intrusion Detection System (IDS) detects any suspicious activity, it will generate several alarms referring to as security breaches. Unfortunately, the triggered alarms usually are accompanied with huge number of false positives. In this paper, we use root cause analysis to discover the root causes making the IDS triggers these false alarms; most of these root causes are not attacks. Removing the root causes enhances alarms quality in the future. The root cause instigates the IDS to trigger alarms that almost always have similar features. These similar alarms can be clustered together; consequently, we have designed a new clustering technique to group IDS alarms and to produce clusters. Then, each cluster is modeled by a generalized alarm. The generalized alarms related to root causes are converted (by the security analyst) to filters in order to reduce future alarms’ load. The suggested system is a semi-automated system helping the security analyst in specifying the root causes behind these false alarms and in writing accurate filtering rules. The proposed clustering method was verified with three different datasets, and the averaged reduction ratio was about 74% of the total alarms. Application of the new technique to alarms log greatly helps the security analyst in identifying the root causes; and then reduces the alarm load in the future." @default.
- W2090638693 created "2016-06-24" @default.
- W2090638693 creator A5056763353 @default.
- W2090638693 creator A5062416906 @default.
- W2090638693 date "2009-02-01" @default.
- W2090638693 modified "2023-10-16" @default.
- W2090638693 title "Intrusion detection alarms reduction using root cause analysis and clustering" @default.
- W2090638693 cites W1546161684 @default.
- W2090638693 cites W1576154654 @default.
- W2090638693 cites W1600820873 @default.
- W2090638693 cites W1678889691 @default.
- W2090638693 cites W1974364887 @default.
- W2090638693 cites W1987971958 @default.
- W2090638693 cites W1988918299 @default.
- W2090638693 cites W1992419399 @default.
- W2090638693 cites W1996747841 @default.
- W2090638693 cites W2024902563 @default.
- W2090638693 cites W2051224630 @default.
- W2090638693 cites W2073165180 @default.
- W2090638693 cites W2108867737 @default.
- W2090638693 cites W2115149820 @default.
- W2090638693 cites W2129066856 @default.
- W2090638693 cites W2129150932 @default.
- W2090638693 cites W2143692712 @default.
- W2090638693 cites W2152449272 @default.
- W2090638693 cites W2161830378 @default.
- W2090638693 cites W2171975443 @default.
- W2090638693 doi "https://doi.org/10.1016/j.comcom.2008.11.012" @default.
- W2090638693 hasPublicationYear "2009" @default.
- W2090638693 type Work @default.
- W2090638693 sameAs 2090638693 @default.
- W2090638693 citedByCount "80" @default.
- W2090638693 countsByYear W20906386932012 @default.
- W2090638693 countsByYear W20906386932013 @default.
- W2090638693 countsByYear W20906386932014 @default.
- W2090638693 countsByYear W20906386932015 @default.
- W2090638693 countsByYear W20906386932016 @default.
- W2090638693 countsByYear W20906386932017 @default.
- W2090638693 countsByYear W20906386932018 @default.
- W2090638693 countsByYear W20906386932019 @default.
- W2090638693 countsByYear W20906386932020 @default.
- W2090638693 countsByYear W20906386932021 @default.
- W2090638693 countsByYear W20906386932022 @default.
- W2090638693 crossrefType "journal-article" @default.
- W2090638693 hasAuthorship W2090638693A5056763353 @default.
- W2090638693 hasAuthorship W2090638693A5062416906 @default.
- W2090638693 hasConcept C111335779 @default.
- W2090638693 hasConcept C124101348 @default.
- W2090638693 hasConcept C127413603 @default.
- W2090638693 hasConcept C130963320 @default.
- W2090638693 hasConcept C138885662 @default.
- W2090638693 hasConcept C153180895 @default.
- W2090638693 hasConcept C154945302 @default.
- W2090638693 hasConcept C159985019 @default.
- W2090638693 hasConcept C171078966 @default.
- W2090638693 hasConcept C192562407 @default.
- W2090638693 hasConcept C200601418 @default.
- W2090638693 hasConcept C2524010 @default.
- W2090638693 hasConcept C2776836416 @default.
- W2090638693 hasConcept C2779119184 @default.
- W2090638693 hasConcept C33923547 @default.
- W2090638693 hasConcept C35525427 @default.
- W2090638693 hasConcept C38652104 @default.
- W2090638693 hasConcept C41008148 @default.
- W2090638693 hasConcept C41895202 @default.
- W2090638693 hasConcept C64869954 @default.
- W2090638693 hasConcept C73555534 @default.
- W2090638693 hasConcept C739882 @default.
- W2090638693 hasConcept C84945661 @default.
- W2090638693 hasConceptScore W2090638693C111335779 @default.
- W2090638693 hasConceptScore W2090638693C124101348 @default.
- W2090638693 hasConceptScore W2090638693C127413603 @default.
- W2090638693 hasConceptScore W2090638693C130963320 @default.
- W2090638693 hasConceptScore W2090638693C138885662 @default.
- W2090638693 hasConceptScore W2090638693C153180895 @default.
- W2090638693 hasConceptScore W2090638693C154945302 @default.
- W2090638693 hasConceptScore W2090638693C159985019 @default.
- W2090638693 hasConceptScore W2090638693C171078966 @default.
- W2090638693 hasConceptScore W2090638693C192562407 @default.
- W2090638693 hasConceptScore W2090638693C200601418 @default.
- W2090638693 hasConceptScore W2090638693C2524010 @default.
- W2090638693 hasConceptScore W2090638693C2776836416 @default.
- W2090638693 hasConceptScore W2090638693C2779119184 @default.
- W2090638693 hasConceptScore W2090638693C33923547 @default.
- W2090638693 hasConceptScore W2090638693C35525427 @default.
- W2090638693 hasConceptScore W2090638693C38652104 @default.
- W2090638693 hasConceptScore W2090638693C41008148 @default.
- W2090638693 hasConceptScore W2090638693C41895202 @default.
- W2090638693 hasConceptScore W2090638693C64869954 @default.
- W2090638693 hasConceptScore W2090638693C73555534 @default.
- W2090638693 hasConceptScore W2090638693C739882 @default.
- W2090638693 hasConceptScore W2090638693C84945661 @default.
- W2090638693 hasIssue "2" @default.
- W2090638693 hasLocation W20906386931 @default.
- W2090638693 hasOpenAccess W2090638693 @default.
- W2090638693 hasPrimaryLocation W20906386931 @default.
- W2090638693 hasRelatedWork W2090638693 @default.
- W2090638693 hasRelatedWork W2102916185 @default.