Enhancing Intrusion Detection Systems Using Intelligent False Alarm Filter

Enhancing Intrusion Detection Systems Using Intelligent False Alarm Filter

Author: 
Meng, Yuxin
Place: 
Hershey
Publisher: 
IGI Global
Date published: 
2013
Responsibility: 
Kwok, Lam-For, jt.author
Editor: 
Ruiz-Martinez, Antonio
Journal Title: 
Architectures and Protocols for Secure Information Technology Infrastructures
Source: 
Architectures and Protocols for Secure Information Technology Infrastructures
Abstract: 

Intrusion Detection Systems (IDSs) have been widely implemented in various network environments as an essential component for current Information and Communications Technologies (ICT). However, false alarms are a big problem for these systems, in which a large number of IDS alarms, especially false positives, could be generated during their detection. This issue greatly decreases the effectiveness and the efficiency of an IDS and heavily increases the burden on analyzing real alarms. To mitigate this problem, in this chapter, the authors identify and analyze the reasons for causing this problem, present a survey through reviewing some related work in the aspect of false alarm reduction, and introduce a promising solution of constructing an intelligent false alarm filter to refine false alarms for an IDS.

Series: 
Advances in Information Security, Privacy, and Ethics

CITATION: Meng, Yuxin. Enhancing Intrusion Detection Systems Using Intelligent False Alarm Filter edited by Ruiz-Martinez, Antonio . Hershey : IGI Global , 2013. Architectures and Protocols for Secure Information Technology Infrastructures - Available at: https://library.au.int/enhancing-intrusion-detection-systems-using-intelligent-false-alarm-filter