Computer Science ›› 2010, Vol. 37 ›› Issue (4): 67-70.
Previous Articles Next Articles
WANG Xiu-li,HAI Mo,ZHU Jian-ming,ZHANG Ning
Online:
Published:
Abstract: The use of intrusion detection has created the problem to investigate a generally large number of alarms. To solve the problem, a clustering analysis method based on alert cause was presented. The correlative alarms with the same attribute were ranged into a clustering according to their causes. The generalized attributes can describe the common characteristic of the alarms. The method can cut down the number of alarms remarkably, simplify the alert analysis, and analyze the security risk in network and application environment accurately. I}herefore, the corresponding measures can be taken in time.
Key words: Intrusion detection, Alert analysis, Alert clustering, Alert cause, Heuristic algorithm
WANG Xiu-li,HAI Mo,ZHU Jian-ming,ZHANG Ning. Clustering Analysis Method Based on Alert Cause[J].Computer Science, 2010, 37(4): 67-70.
0 / / Recommend
Add to citation manager EndNote|Reference Manager|ProCite|BibTeX|RefWorks
URL: https://www.jsjkx.com/EN/
https://www.jsjkx.com/EN/Y2010/V37/I4/67
Cited