Study of an intrusion event correlation method based on interactive knowledge discovery

Research output: Contribution to journalArticlepeer-review

3 Scopus citations

Abstract

On the basis of analyzing the evolution and drawbacks of current intrusion detection systems (IDS), a novel intrusion event correlation system (ECS) based on interactive knowledge discovery is proposed. ECS is composed of off-line part and on-line part. As the former, FP_Tree and WINEPI algorithms are first introduced to implement interactive knowledge discovery for intrusion events correlation. And the discovered frequent patterns and sequence patterns are converted into associative rules for the inference of intrusion events. As the online part of the ECS, embedded CLIPS inference engine is employed to do event correlation, based on priori knowledge and the associative rules discovered above. Application of the ECS in the integrated network security monitor and defense system named Net-Keeper shows that the proposed system is an open and efficient intrusion event correlation engine.

Original languageEnglish
Pages (from-to)1911-1918
Number of pages8
JournalJisuanji Yanjiu yu Fazhan/Computer Research and Development
Volume41
Issue number11
StatePublished - Nov 2004

Keywords

  • Computer network security
  • Expert system
  • Interactive knowledge discovery
  • Intrusion detection

Fingerprint

Dive into the research topics of 'Study of an intrusion event correlation method based on interactive knowledge discovery'. Together they form a unique fingerprint.

Cite this