Aggregation and correlation of intrusion-detection alerts

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

This paper describes an aggregation and correlation algorithm used in the design and implementation of an intrusion-detection console built on top of the Tivoli Enterprise Console (TEC). The aggregation and correlation algorithm aims at acquiring intrusion-detection alerts and relating them together to expose a more condensed view of the security issues raised by intrusion-detection systems.

Original languageEnglish
Title of host publicationRecent Advances in Intrusion Detection - 4th International Symposium, RAID 2001, Proceedings
EditorsWenke Lee, Ludovic Me, Andreas Wespi
PublisherSpringer Verlag
Pages85-103
Number of pages19
ISBN (Print)3540427023, 9783540427025
Publication statusPublished - 1 Jan 2001
Externally publishedYes
Event4th International Symposium on Recent Advances in Intrusion Detection, RAID 2001 - Davis, United States
Duration: 10 Oct 200112 Oct 2001

Publication series

NameLecture Notes in Computer Science
Volume2212 2212 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference4th International Symposium on Recent Advances in Intrusion Detection, RAID 2001
Country/TerritoryUnited States
CityDavis
Period10/10/0112/10/01

Keywords

  • Alert aggregation
  • Alert correlation
  • Alert data model
  • Intrusion detection

Fingerprint

Dive into the research topics of 'Aggregation and correlation of intrusion-detection alerts'. Together they form a unique fingerprint.

Cite this