A semantic analysis approach to manage IDS alerts flooding | IEEE Conference Publication | IEEE Xplore

A semantic analysis approach to manage IDS alerts flooding


Abstract:

In this paper we propose a new approach to manage alerts flooding in IDSs. The proposed approach uses semantic analysis and ontology engineering techniques to combine and...Show More

Abstract:

In this paper we propose a new approach to manage alerts flooding in IDSs. The proposed approach uses semantic analysis and ontology engineering techniques to combine and fuse two or more raw IDS alerts into one summarized hybrid/meta-alert. Our approach applies a new method based on measuring the semantic similarity between IDS alerts attributes to identify the alerts that are suitable for aggregation and summarization. In contrast to previous works our approach ensures that the aggregated alerts will not lose any valuable information existing in the raw alerts set. The experimental results show that our approach is effective and efficient in fusing massive number of alerts compared to previous works in the area.
Date of Conference: 05-08 December 2011
Date Added to IEEE Xplore: 05 January 2012
ISBN Information:
Conference Location: Melacca, Malaysia

Contact IEEE to Subscribe

References

References is not available for this document.