arrow
返回

Network IDS alert classification with active learning techniques

delete2024-03-01
delete4
PRE
AI
R
Risto Vaarandi *
A
Alejandro Guerra-Manzanares
DOI:10.1016/j.jisa.2023.103687delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
A Network Intrusion Detection System (NIDS) is a widely used security monitoring technology for detecting attacks against network services, beaconing activity of infected end user nodes, malware propagation, and other types of malicious network traffic. Unfortunately, NIDS technologies are known to generate a large number of alerts, with a significant proportion of them having low importance. During the last two decades, many machine learning and data mining based approaches have been proposed for highlighting high-importance alerts that require human attention. However, NIDS alert classification systems based on active learning have received marginal attention in the specialized research literature. This neglects the potential benefits of active learning which involves a human expert in the machine learning model life cycle. The current paper fills this research gap and studies the use of active learning techniques for NIDS alert classification.
Keyword:
NIDS alert classification
Active learning
Security alert prioritization
Network security
Machine leaching

期刊

Journal of Information Security and Applications 封面图
Journal of Information Security and Applications
IF:
3.7
论文数:
2.0K
被引数:
4.9K

机构

N
New York University
学者数:
4.4W
论文数: 3.9W
被引数: 5.8W
T
Tallinn University of Technology
学者数:
4.3K
论文数: 3.1K
被引数: 4.5K
引用论文

引用论文

err分享
err收藏
Reactivities of the N-Atom-inserted Ligands, NSC(NR2)S2− and SN=C(NR2)S2−, in Iridium(III) Complexes
err2011-07-09
err0
PREAI
errKeita Ariyoshi; Takayoshi Suzuki; James M Mayer; Masaaki Kojima
err分享
err收藏
err分享
err收藏
err分享
err收藏
Glass Formation in Carbonate Systems
err2006-06-02
err0
PREAI
errR. K. DATTA; D. M. ROY; S. P. FAILE; O. F. TUTTLE
err分享
err收藏
err
IF0
err
err0
PREAI
err
err分享
err收藏
Enhancing IDS performance through comprehensive alert post-processing
err2013-09-01
err27
PREAI
errSpathoulas, Georgios P.; Katsikas, Sokratis K.
err分享
err收藏
Featureless Discovery of Correlated and False Intrusion Alerts
err2020-01-01
err6
errOAAI
errKidmose, Egon; Stevanovic, Matija; Brandbyge, Soren; Pedersen, Jens M.
err分享
err收藏
Security Operations Center: A Systematic Study and Open Challenges
err2020-01-01
err87
errOAAI
errVielberth, Manfred; Boehm, Fabian; Fichtinger, Ines; Pernul, Guenther
err分享
err收藏
学者 查看更多内容