Title : ( E‐correlator: an entropy‐based alert correlation system )
Authors: Mohammad GhasemiGol , Abbas Ghaemi Bafghi ,Abstract
With the rapid size and complexity growth of computer networks, network supervisors are now facing a new problem, which is to analyze and manage the large amounts of security alerts that can be generated by security devices. Alert correlation systems attempt to solve this problem by finding the similarity and causality relationships between raw alerts and providing high-level view of the network under surveillance. Several alert correlation methods have been proposed recently to detect known attack scenarios. This paper focuses on how to develop an intrusion-alert correlation system according to the information existed in the raw alerts without using any predefined knowledge. For this purpose, first, we define the concept of alert partial entropy to find the alert clusters with the same information. Then, we represent the alert clusters by an intelligible notation called hyper-alerts. The network supervisor can reduce the number of hyper-alerts based on the principle of maximum entropy or by using the concept of hyper-alerts partial entropy. For more visualization, we define the hyper-alerts graph, which provides a global view of intrusion alerts. Our results show that the proposed entropy-based alert correlation system (E-correlator) can simplify the analysis of large number of alerts. We achieved the promising reduction ratio of 99.98% in LLS_DDOS_1.0 attack scenario in DARPA2000 dataset while the constructed hyper-alerts have enough information to discover the attacker, the victim, and the attack scenario. Copyright
Keywords
, intrusion detection system; alert correlation; information theory; alert partial entropy; hyper, alert partial entropy@article{paperid:1057665,
author = {GhasemiGol, Mohammad and Ghaemi Bafghi, Abbas},
title = {E‐correlator: an entropy‐based alert correlation system},
journal = {Security and Communication Networks},
year = {2015},
volume = {8},
number = {5},
month = {March},
issn = {1939-0114},
pages = {822--836},
numpages = {14},
keywords = {intrusion detection system; alert correlation; information theory; alert partial entropy; hyper-alert partial entropy},
}
%0 Journal Article
%T E‐correlator: an entropy‐based alert correlation system
%A GhasemiGol, Mohammad
%A Ghaemi Bafghi, Abbas
%J Security and Communication Networks
%@ 1939-0114
%D 2015