DONG Xiao-mei, YU Ge, SUN Jing-ru, et al. An Alert Correlation and Analysis Algorithm Based on Frequent Pattern Mining[J]. Acta Electronica Sinica, 2005, 33(8): 1356-1359.
DOI:
DONG Xiao-mei, YU Ge, SUN Jing-ru, et al. An Alert Correlation and Analysis Algorithm Based on Frequent Pattern Mining[J]. Acta Electronica Sinica, 2005, 33(8): 1356-1359.DOI:
An Alert Correlation and Analysis Algorithm Based on Frequent Pattern Mining
An intrusion detection and response cooperation model was proposed.Incorporating the intrusion tolerance idea
the Intrusion Detection Message Exchange Format (IDMEF) was extended and a suspicious degree attribute was added.So suspicious events as well as intrusions can be reported to the cooperation components.An alert correlation and analysis algorithm was proposed
which was based on the modified CLOSET frequent close pattern mining algorithm.The algorithm can help the cooperation components in a distributed intrusion detection and response cooperation system to correlate and analyze the alerts received to make appropriate responses.To meet this purpose
the CLOSET algorithm was modified to obtain frequent close patterns according to a minimum support and a minimum suspicion degree.Experimental results show that when applying the algorithm
the amount of alerts can be effectively decreased.And appropriate responses can be made according to all the suspicious and intrusion events.