Suppr超能文献

An Efficient Alert Aggregation Method Based on Conditional Rough Entropy and Knowledge Granularity.

作者信息

Sun Jiaxuan, Gu Lize, Chen Kaiyuan

机构信息

Institute of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China.

出版信息

Entropy (Basel). 2020 Mar 12;22(3):324. doi: 10.3390/e22030324.

Abstract

With the emergence of network security issues, various security devices that generate a large number of logs and alerts are widely used. This paper proposes an alert aggregation scheme that is based on conditional rough entropy and knowledge granularity to solve the problem of repetitive and redundant alert information in network security devices. Firstly, we use conditional rough entropy and knowledge granularity to determine the attribute weights. This method can determine the different important attributes and their weights for different types of attacks. We can calculate the similarity value of two alerts by weighting based on the results of attribute weighting. Subsequently, the sliding time window method is used to aggregate the alerts whose similarity value is larger than a threshold, which is set to reduce the redundant alerts. Finally, the proposed scheme is applied to the CIC-IDS 2018 dataset and the DARPA 98 dataset. The experimental results show that this method can effectively reduce the redundant alerts and improve the efficiency of data processing, thus providing accurate and concise data for the next stage of alert fusion and analysis.

摘要
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/6c2d/7516779/db72c51290f2/entropy-22-00324-g001.jpg

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验