Applying Alert Correlation Method In Network Intrusion Detection System

Wj Li,Df Zhang,Xd Yang
2004-01-01
Abstract:Traditional intrusion detection systems (IDSs)focus on low-level attacks or anomalies, and they raise alerts independently, though there may be logical connections between them. With the development of network security infrastructure and technology, it seems that attackers continuously adjust and upgrade their intrusion methods to escape from security inspection. Some kinds of intricate intrusion mode are widely used now. When meeting with these intricate intrusions such as distributed denial of service (DDoS), network administrator may find alerts with unmanageable amount and mixed true alerts with false alerts. As a result, it is difficult for intrusion response systems and users to understand the alerts and take appropriate actions. This is why alert correlation technology has developed with such a striking speed in recent years. This paper presents a method to apply alert correlation in cooperative intrusion detection framework gives an implementation of the system prototype and illustrates the preliminary experiment results.
What problem does this paper attempt to address?