An Algorithm of Alert Correlation Based on Address Correlation Graph in Distributed Intrusion Detection System

DUAN Hai-xin,YU Xue-li,WANG Lan-jia
DOI: https://doi.org/10.3321/j.issn:1000-8608.2005.z1.032
2005-01-01
Abstract:The alert flood of current IDSes often overwhelms the security administrators,which largely decreases the effectiveness of IDS.The correlation of original alerts plays an important role in distributed IDS,which can draw out the effective attacks from a large number of alerts,and analyze the real intension of attackers.In this paper,the merits and defects of typical correlation algorithms are analyzed.An algorithm of alert correlation based on address correlation graph(ACG) is proposed here.The algorithm can be used to analyze the original alerts with ACG model,which can get the intrusion path of attackers through the relation and steps of different attacks,and then analyze the intension of attackers.The algorithm is easy to be implemented because it does not depend on a predefined base of correlation knowledge or a forehand training of correlation model.
What problem does this paper attempt to address?