An Approach to Meta-Alert Generation to Reduce Analyst Workload
DOI:
https://doi.org/10.18486/ijcsnt/7.2.092Keywords:
Alert Merging, Alert Reduction, Stealth Port Scanning, Intrusion Detection SystemAbstract
This is the era of Technology. Digitization becomes a trend today. Organizations are trying to become more digitized than one another because of the growth in a number of internet users. The Internet is a popular place among criminals too. They perform criminal activities for their benefit over the internet. These actions are called cybercrimes. The reason for increased cybercrime is the enhanced use of the internet. These days millions of attacks are being performed each year. The prodigious number of attacks makes the data under potential infringement. So as far as concerned, cybersecurity becomes the most important issue these days. In recent years intrusions are increasing rapidly that result in compromise with the protection of user data. Intrusion detection systems are used to detects and prevents these intrusions. Port Scanning is a common type of intrusions. Generally, it takes place as the first step of an intrusion. Port-scanner is software intended to probe a machine for open ports. Port scanning attacks result in huge amount of network alerts which is manually analyzed by the network administrator. In the proposed work, a novel approach is presented to minimize this huge amount of the similar alerts of stealth port scanning attack by generating meta-alert. To validate the performance of the proposed method an experiment has been carried out using MACCDC dataset. And it is observed that 99.65% alerts are significantly reduced.
References
Roesch M. Snort—Lightweight intrusion detection for networks. Proceedings of the 13th USENIX Conference on System Administration 1999; pp. 229–238.
Chyssler T, Burschka S, Semling M, Lingvall T and Burbeck K. Alarm reduction and correlation in intrusion detection systems. In: GI Special Interest Group SIDAR Workshop, DIMVA, Dortmund, Germany; 2004.
Farhadi H, AmirHaeri M and Khansari AM. Alert correlation and prediction using data mining and HMM. The ISC International Journal of Information Security 2011; pp. 1–25.
Valeur F, Vigna G, Kruegel C and Kemmerer RA. Comprehensive approach to intrusion detection alert correlation. IEEE Transactions on Dependable and Secure Computing 2004; 1(3): 146–169. DOI: 10.1109/TDSC.2004.21. DOI: https://doi.org/10.1109/TDSC.2004.21
Siraj A and Vaughn RB. Alert correlation with abstract incident modeling in a multi-sensor environment. International Journal of Computer Science and Network Security 2007; pp. 8–19.
Treinen JJ and Thurimella R. A framework for the application of association rule mining in large intrusion detection. In: Recent Advances in Intrusion Detection. Berlin, Heidelberg: Springer-Verlag; 2006. pp. 1–18. DOI: https://doi.org/10.1007/11856214_1
Julisch K and Dacier M. Mining intrusion detection alarms for actionable knowledge. Proceedings of the Eighth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining 2002; pp. 366–375. DOI: https://doi.org/10.1145/775047.775101
Mid-Atlantic Collegiate Cyber Defense Competition (MACCDC). 2018. Available at: http://www.netresec.com/?page=MACCDC.
Lyon G. Nmap—Free security scanner for network exploration and security audits. 2009.
Jacobson V, Leres C and McCanne S. Libpcap. Lawrence Berkeley Laboratory, Berkeley, CA. Initial public release, 1994.
Postel J. Transmission Control Protocol. RFC 793, 1981. DOI: https://doi.org/10.17487/RFC793
Cuppens F. Managing alerts in a multi-intrusion detection environment. Proceedings of the 17th Annual Computer Security Applications Conference (ACSAC); 2001.
Cuppens F and Miege A. Alert correlation in a cooperative intrusion detection framework. Proceedings of the IEEE Symposium on Security and Privacy 2002; pp. 202–215. DOI: https://doi.org/10.1109/SECPRI.2002.1004372
Ning P, Cui Y and Reeves DS. Constructing attack scenarios through correlation of intrusion alerts. Proceedings of the 9th ACM Conference on Computer and Communications Security 2002; pp. 245–254. DOI: https://doi.org/10.1145/586110.586144
Morin B, Me L, Debar H and Ducasse M. M2D2: A formal data model for IDS alert correlation. In: Recent Advances in Intrusion Detection (RAID). Springer; 2002. pp. 115–137. DOI: https://doi.org/10.1007/3-540-36084-0_7
Downloads
Published
Issue
Section
License
Copyright (c) 2018 Deeksha Kushwah, Rajni Ranjan Singh Makwana

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.