Design and Implementation of Alert Information Correlation Model

Jin-ze PEI,Hua-ping HU,Chen-lin HUANG
DOI: https://doi.org/10.3969/j.issn.1001-3695.2006.03.033
2006-01-01
Abstract:Conventional network security protection is facing a great challenge of coordinated and distributed attack,so distributed intrusion detection technology is required.Fusing multi-kinds of IDS alerts can effectively improve warning veracity.Based on annotation to alert correlation definition renewedly,the paper designed and implemented layered correlation model with real-time response mechanism.The model is much adaptive,each layer of which can do its work independently.At last,the function of fusing alert information is implemented,which can resolve problems of management of alerts,false negative and false positive better and can warn according to attack intention identified.
What problem does this paper attempt to address?