Intelligent alarm filter using knowledge-based alert verification in network intrusion detection

Yuxin MENG, Wenjuan LI, Lam-For KWOK

Research output: Chapter in Book/Report/Conference proceedingChapters

15 Citations (Scopus)

Abstract

Network intrusions have become a big challenge to current network environment. Thus, network intrusion detection systems (NIDSs) are being widely deployed in various networks aiming to detect different kinds of network attacks (e.g., Trojan, worms). However, in real settings, a large number of alarms can be generated during the detection procedure, which greatly decrease the effectiveness of these intrusion detection systems. To mitigate this problem, we advocate that constructing an alarm filter is a promising solution. In this paper, we design and develop an intelligent alarm filter to help filter out NIDS alarms by means of knowledge-based alert verification. In particular, our proposed method of knowledge-based alert verification employs a rating mechanism in terms of expert knowledge to classify incoming NIDS alarms. We implemented and evaluated this intelligent knowledge-based alarm filter in a network environment. The experimental results show that the developed alarm filter can accurately filter out a number of NIDS alarms and achieve a better outcome. Copyright © 2012 Springer-Verlag Berlin Heidelberg.

Original languageEnglish
Title of host publicationFoundations of intelligent systems: 20th International Symposium, ISMIS 2012, Macau, China, December 4-7, 2012, proceedings
EditorsLi CHEN, Alexander FELFERNIG, Jiming LIU, Zbigniew W. RAŚ
Place of PublicationBerlin
PublisherSpringer
Pages115-124
ISBN (Electronic)9783642346248
ISBN (Print)9783642346231
DOIs
Publication statusPublished - 2012

Citation

Meng, Y., Li, W., & Kwok, L.-F. (2012). Intelligent alarm filter using knowledge-based alert verification in network intrusion detection. In L. Chen, A. Felfernig, J. Liu, & Z. W. Raś (Eds.), Foundations of intelligent systems: 20th International Symposium, ISMIS 2012, Macau, China, December 4-7, 2012, proceedings (pp. 115-124). Springer. https://doi.org/10.1007/978-3-642-34624-8_14

Keywords

  • Intelligent system
  • Alarm filtration
  • Alert verification
  • Knowledge representation and integration
  • Network intrusion detection

Fingerprint

Dive into the research topics of 'Intelligent alarm filter using knowledge-based alert verification in network intrusion detection'. Together they form a unique fingerprint.