Return
Network IDS alert classification with active learning techniques
DOI:10.1016/j.jisa.2023.103687.png)
Abstract
En 中文
A Network Intrusion Detection System (NIDS) is a widely used security monitoring technology for detecting attacks against network services, beaconing activity of infected end user nodes, malware propagation, and other types of malicious network traffic. Unfortunately, NIDS technologies are known to generate a large number of alerts, with a significant proportion of them having low importance. During the last two decades, many machine learning and data mining based approaches have been proposed for highlighting high-importance alerts that require human attention. However, NIDS alert classification systems based on active learning have received marginal attention in the specialized research literature. This neglects the potential benefits of active learning which involves a human expert in the machine learning model life cycle. The current paper fills this research gap and studies the use of active learning techniques for NIDS alert classification.
Keywords:
NIDS alert classification
Active learning
Security alert prioritization
Network security
Machine leaching
Journal
IF:
3.7
Papers:
2.0K
Citations:
4.9K
Organization
Cited Papers
Reactivities of the N-Atom-inserted Ligands, NSC(NR2)S2− and SN=C(NR2)S2−, in Iridium(III) Complexes
IDPS Signature Classification Based on Active Learning With Partial Supervision From Network Security Experts
IEEE ACCESS
IF3.6

