Research on the Method of Reducing False Positives with Periodicity

LI Dong,LI Zhi-tang,LEI Jie
2009-01-01
Abstract:NIDS(Network Intrusion Detection System) is an effective device to discover network security events.Nevertheless it will produce a large number of false positives in real network,which makes security analysis in real-time very difficult.This paper puts forward a new idea that alerts with periodicity are false positives,and filters relevant redundant alerts by the discovery and determination of periodicity.This algorithm has been tested in a branch network of CERNET(China Education and Research Network),and over 90% alerts can be removed in this way.Meanwhile some root causes that trigger periodic alerts can be discovered,it can be validated that these alerts are false positives indeed.
What problem does this paper attempt to address?