arrow
Return

Network IDS alert classification with active learning techniques

delete2024-03-01
delete4
PRE
AI
R
Risto Vaarandi *
A
Alejandro Guerra-Manzanares
DOI:10.1016/j.jisa.2023.103687delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
A Network Intrusion Detection System (NIDS) is a widely used security monitoring technology for detecting attacks against network services, beaconing activity of infected end user nodes, malware propagation, and other types of malicious network traffic. Unfortunately, NIDS technologies are known to generate a large number of alerts, with a significant proportion of them having low importance. During the last two decades, many machine learning and data mining based approaches have been proposed for highlighting high-importance alerts that require human attention. However, NIDS alert classification systems based on active learning have received marginal attention in the specialized research literature. This neglects the potential benefits of active learning which involves a human expert in the machine learning model life cycle. The current paper fills this research gap and studies the use of active learning techniques for NIDS alert classification.
Keywords:
NIDS alert classification
Active learning
Security alert prioritization
Network security
Machine leaching

Journal

Journal of Information Security and Applications cover
Journal of Information Security and Applications
IF:
3.7
Papers:
2.0K
Citations:
4.9K

Organization

N
New York University
Scholars:
4.4W
Papers: 3.9W
Citations: 5.8W
T
Tallinn University of Technology
Scholars:
4.3K
Papers: 3.1K
Citations: 4.5K
Cited Papers

Cited Papers

errShare
errSave
Reactivities of the N-Atom-inserted Ligands, NSC(NR2)S2− and SN=C(NR2)S2−, in Iridium(III) Complexes
err2011-07-09
err0
PREAI
errKeita Ariyoshi; Takayoshi Suzuki; James M Mayer; Masaaki Kojima
errShare
errSave
errShare
errSave
errShare
errSave
Glass Formation in Carbonate Systems
err2006-06-02
err0
PREAI
errR. K. DATTA; D. M. ROY; S. P. FAILE; O. F. TUTTLE
errShare
errSave
err
IF0
err
err0
PREAI
err
errShare
errSave
Enhancing IDS performance through comprehensive alert post-processing
err2013-09-01
err27
PREAI
errSpathoulas, Georgios P.; Katsikas, Sokratis K.
errShare
errSave
Featureless Discovery of Correlated and False Intrusion Alerts
err2020-01-01
err6
errOAAI
errKidmose, Egon; Stevanovic, Matija; Brandbyge, Soren; Pedersen, Jens M.
errShare
errSave
Security Operations Center: A Systematic Study and Open Challenges
err2020-01-01
err87
errOAAI
errVielberth, Manfred; Boehm, Fabian; Fichtinger, Ines; Pernul, Guenther
errShare
errSave
researcher View more