Network Security White Papers
Clustering Intrusion Detection Alarms to Support Root Cause Analysis
Overview It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. This paper presents a new approach for handling intrusion detection alarms more efficiently. Central to this approach is the notion that each alarm occurs for a reason, which is referred to as the alarm's root causes. This paper observes that a few dozens of rather persistent root causes generally account for over 90% of the alarms that an intrusion detection system triggers. Therefore, it argues that alarms should be handled by identifying and removing the most predominant and persistent root causes. To make this paradigm practicable, the paper proposes a novel alarm clustering method that supports the human analyst in identifying root causes.
| Publisher | Association for Computing Machinery | File Format | |
|---|---|---|---|
| Date Published | September 2002 | ||
| Format | White Papers | ||
| Topics | |||



