Back to Search Start Over

Alert Management System using K-means Based Genetic for IDS

Authors :
Fatemeh Charlank Bakhtiari
Mohammad Masdari
Source :
International Journal of Security and Its Applications. 8:109-118
Publication Year :
2014
Publisher :
NADIA, 2014.

Abstract

One of the most important tools in security field is Intrusion Detection System. The aim of the IDS is to monitor suspicious network traffic and generate alerts. These systems are known to generate numerousfalse positive alerts. Analyzing the alerts manually by security expert need more time and could be error prone.Another problem with IDS is Identifying attack types and generating correct alerts related to attacks.we introducenew alert management systems to overcome mentioned problems. Alert management systems help security experts to manage alerts and produce a high level view of alerts. In this paper a new alert clustering algorithm for IDS Alert Management System proposed that uses the K-mean Based Genetic (KBG). The proposed algorithm reduces alerts and detects false positive alerts. By the experimental results on DARPA KDD cup 98 the system is able to cluster and classify alerts and causes reducing false positive alerts considerably.

Details

ISSN :
17389976
Volume :
8
Database :
OpenAIRE
Journal :
International Journal of Security and Its Applications
Accession number :
edsair.doi...........85f575dcc2b52e98243270dd59b3b8c8
Full Text :
https://doi.org/10.14257/ijsia.2014.8.5.11