An Approach to Meta-Alert Generation to Reduce Analyst Workload

Authors

  • Deeksha Kushwah Madhav Institute of Technology & Science image/svg+xml
  • Rajni Ranjan Singh Makwana Madhav Institute of Technology & Science image/svg+xml

DOI:

https://doi.org/10.18486/ijcsnt/7.2.092

Keywords:

Alert Merging, Alert Reduction, Stealth Port Scanning, Intrusion Detection System

Abstract

This is the era of Technology. Digitization becomes a trend today. Organizations are trying to become more digitized than one another because of the growth in a number of internet users. The Internet is a popular place among criminals too. They perform criminal activities for their benefit over the internet. These actions are called cybercrimes. The reason for increased cybercrime is the enhanced use of the internet. These days millions of attacks are being performed each year. The prodigious number of attacks makes the data under potential infringement. So as far as concerned, cybersecurity becomes the most important issue these days. In recent years intrusions are increasing rapidly that result in compromise with the protection of user data. Intrusion detection systems are used to detects and prevents these intrusions. Port Scanning is a common type of intrusions. Generally, it takes place as the first step of an intrusion. Port-scanner is software intended to probe a machine for open ports. Port scanning attacks result in huge amount of network alerts which is manually analyzed by the network administrator. In the proposed work, a novel approach is presented to minimize this huge amount of the similar alerts of stealth port scanning attack by generating meta-alert. To validate the performance of the proposed method an experiment has been carried out using MACCDC dataset. And it is observed that 99.65% alerts are significantly reduced.

References

Roesch M. Snort—Lightweight intrusion detection for networks. Proceedings of the 13th USENIX Conference on System Administration 1999; pp. 229–238.

Chyssler T, Burschka S, Semling M, Lingvall T and Burbeck K. Alarm reduction and correlation in intrusion detection systems. In: GI Special Interest Group SIDAR Workshop, DIMVA, Dortmund, Germany; 2004.

Farhadi H, AmirHaeri M and Khansari AM. Alert correlation and prediction using data mining and HMM. The ISC International Journal of Information Security 2011; pp. 1–25.

Valeur F, Vigna G, Kruegel C and Kemmerer RA. Comprehensive approach to intrusion detection alert correlation. IEEE Transactions on Dependable and Secure Computing 2004; 1(3): 146–169. DOI: 10.1109/TDSC.2004.21. DOI: https://doi.org/10.1109/TDSC.2004.21

Siraj A and Vaughn RB. Alert correlation with abstract incident modeling in a multi-sensor environment. International Journal of Computer Science and Network Security 2007; pp. 8–19.

Treinen JJ and Thurimella R. A framework for the application of association rule mining in large intrusion detection. In: Recent Advances in Intrusion Detection. Berlin, Heidelberg: Springer-Verlag; 2006. pp. 1–18. DOI: https://doi.org/10.1007/11856214_1

Julisch K and Dacier M. Mining intrusion detection alarms for actionable knowledge. Proceedings of the Eighth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining 2002; pp. 366–375. DOI: https://doi.org/10.1145/775047.775101

Mid-Atlantic Collegiate Cyber Defense Competition (MACCDC). 2018. Available at: http://www.netresec.com/?page=MACCDC.

Lyon G. Nmap—Free security scanner for network exploration and security audits. 2009.

Jacobson V, Leres C and McCanne S. Libpcap. Lawrence Berkeley Laboratory, Berkeley, CA. Initial public release, 1994.

Postel J. Transmission Control Protocol. RFC 793, 1981. DOI: https://doi.org/10.17487/RFC793

Cuppens F. Managing alerts in a multi-intrusion detection environment. Proceedings of the 17th Annual Computer Security Applications Conference (ACSAC); 2001.

Cuppens F and Miege A. Alert correlation in a cooperative intrusion detection framework. Proceedings of the IEEE Symposium on Security and Privacy 2002; pp. 202–215. DOI: https://doi.org/10.1109/SECPRI.2002.1004372

Ning P, Cui Y and Reeves DS. Constructing attack scenarios through correlation of intrusion alerts. Proceedings of the 9th ACM Conference on Computer and Communications Security 2002; pp. 245–254. DOI: https://doi.org/10.1145/586110.586144

Morin B, Me L, Debar H and Ducasse M. M2D2: A formal data model for IDS alert correlation. In: Recent Advances in Intrusion Detection (RAID). Springer; 2002. pp. 115–137. DOI: https://doi.org/10.1007/3-540-36084-0_7

Downloads

Published

2018-08-31

How to Cite

An Approach to Meta-Alert Generation to Reduce Analyst Workload. (2018). International Journal of Communication Systems and Network Technologies, 7(2), 40-47. https://doi.org/10.18486/ijcsnt/7.2.092