Parallel Network Alert Management System For IDS False Positive Reduction

Every secure system has the possibility to fail. Therefore, extra effort should be taken to protect these systems. Intrusion detection systems (IDSs) had been proposed with the aim of providing extra protection to security systems. IDS is a powerful computer security system used to secure the comput...

Full description

Saved in:
Bibliographic Details
Main Author: el-Taj, Homam Reda Kamel
Format: Thesis
Language:English
Published: 2011
Subjects:
Online Access:http://eprints.usm.my/41856/1/HOMAM_REDA_KAMEL_EL-TAJ.pdf
Tags: Add Tag
No Tags, Be the first to tag this record!
Description
Summary:Every secure system has the possibility to fail. Therefore, extra effort should be taken to protect these systems. Intrusion detection systems (IDSs) had been proposed with the aim of providing extra protection to security systems. IDS is a powerful computer security system used to secure the computer environments. These systems trigger thousands of alerts per day, which prompt security analysts to verify each alert for relevance and severity based on an aggregation and correlation criterion. Several aggregation and correlation methods have been proposed to collect these alerts.