Article ID | Journal | Published Year | Pages | File Type |
---|---|---|---|---|
10341816 | Information Security Technical Report | 2005 | 15 Pages |
Abstract
In this paper, we present two orthogonal and complementary approaches to reduce the number of false positives in intrusion detection using alert postprocessing by data mining and machine learning. Moreover, these two techniques, because of their complementary nature, can be used together in an alert-management system. These concepts have been verified on a variety of data sets, and achieved a significant reduction in the number of false positives in both simulated and real environments.
Related Topics
Physical Sciences and Engineering
Computer Science
Computer Networks and Communications
Authors
Tadeusz Pietraszek, Axel Tanner,