Journal of System Simulation ›› 2016, Vol. 28 ›› Issue (6): 1336-1343.

Previous Articles     Next Articles

Research of Intrusion Alert Aggregation Based on Spatial and Temporal Density

Zhang Jing, Wang Hengjun, Li Junquan, Yu Bin   

  1. PLA Information Engineering University, Zhengzhou 450004, China
  • Received:2015-04-29 Revised:2015-07-24 Online:2016-06-08 Published:2020-06-08

Abstract: Distributed Intrusion Detection System has created the problem to investigate a mass of duplicate alerts and high false positive rate in practical applications. Based on DBSCAN, density based spatial and temporal clustering of applications with noise (DBS&TCAN) algorithm was proposed by introducing temporal density. The approach aggregated partial alerts based on spatial density, and merges partial aggregation on the basis of temporal density. The effectiveness of the algorithm was demonstrated by the intrusion detection evaluation dataset. The comparative experiments and analysis show that the algorithm is effective in alert aggregation and gives better results in terms of real time.

Key words: Intrusion detection system, alert aggregation, temporal density, DBSCAN, DBS&TCAN;, real time

CLC Number: