Network Security White Papers

Clustering Intrusion Detection Alarms to Support Root Cause Analysis

Overview It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. This paper presents a new approach for handling intrusion detection alarms more efficiently. Central to this approach is the notion that each alarm occurs for a reason, which is referred to as the alarm's root causes. This paper observes that a few dozens of rather persistent root causes generally account for over 90% of the alarms that an intrusion detection system triggers. Therefore, it argues that alarms should be handled by identifying and removing the most predominant and persistent root causes. To make this paradigm practicable, the paper proposes a novel alarm clustering method that supports the human analyst in identifying root causes.

Further White Paper Details
PublisherAssociation for Computing Machinery File FormatPDF
Date PublishedSeptember 2002
FormatWhite Papers   
Topics
E4 embraces web 2.0 audience

E4 embraces web 2.0 audience

Case study: How the Channel 4's teen channel put its mind to building a community website... more

Cheat Sheet: Cloud computing

Cheat Sheet: Cloud computing

A tech storm is brewing...  more


Quick Sitemap Links: