Application of Anomaly Detection in Alert Correlation Analysis

王娟,秦志光,叶李,靳京
DOI: https://doi.org/10.3969/j.issn.1009-3443.2009.03.016
2009-01-01
Abstract:A classic statistic model namely Mean and Standard Deviation Model(MSDM) was used to control time for alert correlation analysis in order to make the alert correlation more meaningful and efficient.Taking false alerts as the background flow and true alerts as the anomaly of the alert flow,MSDM detected the anomaly of the alert flow and offered the abnormal time slice to correlation analysis.Correlation process only correlated the alerts which were in the abnormal time slice.Simulation results show that this new method can detect anomaly alert intensities and offer time control to get more meaningful correlated results.Focused on the alerts in anomaly time,this method can save much time and energy of network administrators.
What problem does this paper attempt to address?