Asset Details
MbrlCatalogueTitleDetail
Do you wish to reserve the book?
An Efficient Alert Aggregation Method Based on Conditional Rough Entropy and Knowledge Granularity
by
Sun, Jiaxuan
, Gu, Lize
, Chen, Kaiyuan
in
alert aggregation
/ attribute similarity
/ conditional rough entropy
/ knowledge granularity
2020
Hey, we have placed the reservation for you!
By the way, why not check out events that you can attend while you pick your title.
You are currently in the queue to collect this book. You will be notified once it is your turn to collect the book.
Oops! Something went wrong.
Looks like we were not able to place the reservation. Kindly try again later.
Are you sure you want to remove the book from the shelf?
Oops! Something went wrong.
While trying to remove the title from your shelf something went wrong :( Kindly try again later!
Do you wish to request the book?
An Efficient Alert Aggregation Method Based on Conditional Rough Entropy and Knowledge Granularity
by
Sun, Jiaxuan
, Gu, Lize
, Chen, Kaiyuan
in
alert aggregation
/ attribute similarity
/ conditional rough entropy
/ knowledge granularity
2020
Please be aware that the book you have requested cannot be checked out. If you would like to checkout this book, you can reserve another copy
We have requested the book for you!
Your request is successful and it will be processed during the Library working hours. Please check the status of your request in My Requests.
Oops! Something went wrong.
Looks like we were not able to place your request. Kindly try again later.
An Efficient Alert Aggregation Method Based on Conditional Rough Entropy and Knowledge Granularity
Journal Article
An Efficient Alert Aggregation Method Based on Conditional Rough Entropy and Knowledge Granularity
2020
Request Book From Autostore
and Choose the Collection Method
Overview
With the emergence of network security issues, various security devices that generate a large number of logs and alerts are widely used. This paper proposes an alert aggregation scheme that is based on conditional rough entropy and knowledge granularity to solve the problem of repetitive and redundant alert information in network security devices. Firstly, we use conditional rough entropy and knowledge granularity to determine the attribute weights. This method can determine the different important attributes and their weights for different types of attacks. We can calculate the similarity value of two alerts by weighting based on the results of attribute weighting. Subsequently, the sliding time window method is used to aggregate the alerts whose similarity value is larger than a threshold, which is set to reduce the redundant alerts. Finally, the proposed scheme is applied to the CIC-IDS 2018 dataset and the DARPA 98 dataset. The experimental results show that this method can effectively reduce the redundant alerts and improve the efficiency of data processing, thus providing accurate and concise data for the next stage of alert fusion and analysis.
Publisher
MDPI,MDPI AG
This website uses cookies to ensure you get the best experience on our website.