PlumX Metrics
Embed PlumX Metrics

Reducing false positives in anomaly detectors through fuzzy alert aggregation

Information Fusion, ISSN: 1566-2535, Vol: 10, Issue: 4, Page: 300-311
2009
  • 38
    Citations
  • 0
    Usage
  • 76
    Captures
  • 0
    Mentions
  • 0
    Social Media
Metric Options:   Counts1 Year3 Year

Metrics Details

  • Citations
    38
    • Citation Indexes
      38
  • Captures
    76

Article Description

In this paper we focus on the aggregation of IDS alerts, an important component of the alert fusion process. We exploit fuzzy measures and fuzzy sets to design simple and robust alert aggregation algorithms. Exploiting fuzzy sets, we are able to robustly state whether or not two alerts are “close in time”, dealing with noisy and delayed detections. A performance metric for the evaluation of fusion systems is also proposed. Finally, we evaluate the fusion method with alert streams from anomaly-based IDS.

Provide Feedback

Have ideas for a new metric? Would you like to see something else here?Let us know