An alert correlation approach based on security operator's knowledge and preferences

Journal of Applied Non-Classical Logics 20 (1-2):7-37 (2010)
  Copy   BIBTEX


One of the major problems of intrusion detection concerns the large amount of alerts that intrusion detection systems (IDS) produce. Security operator who analyzes alerts and takes decisions, is often submerged by the high number of alerts to analyze. In this paper, we present a new alert correlation approach based on knowledge and preferences of security operators. This approach, which is complementary to existing ones, allows to rank-order produced alerts on the basis of a security operator knowledge about the system, used IDS and his preferences about alerts that he wants to analyze or to ignore. Our approach is based on the development of a new non-classical logic for representing preferences, called FO-MQCL (First Order - Minimal Qualitative Choice Logic). Our logic extends a fragment of the first order logic by adding a new logical connective. The general idea is to present only alerts that fully fit security operator's preferences and knowledge. And if needed, less preferred alerts can also be presented.



    Upload a copy of this work     Papers currently archived: 92,873

External links

Setup an account with your affiliations in order to access resources via your University's proxy server

Through your library


Added to PP

20 (#788,228)

6 months
2 (#1,249,707)

Historical graph of downloads
How can I increase my downloads?

Citations of this work

No citations found.

Add more citations

References found in this work

Qualitative choice logic.Gerhard Brewka, Salem Benferhat & Daniel Le Berre - 2004 - Artificial Intelligence 157 (1-2):203-237.

Add more references