Enhanced Alert Correlation Framework for Heterogeneous Log

Management of intrusion alarms particularly in identifying malware attack is becoming more demanding due to large amount of alert produced by low-level detectors. Alert correlation can provide high-level view of intrusion alerts but incapable of handling large amount of alarm. This paper proposes an...

Full description

Bibliographic Details
Main Authors: Yusof, R., Selamat, S. R., Sahib, S., Mas'ud, M. Z., Abdollah, M. F.
Format: Conference or Workshop Item
Language:English
Published: 2011
Subjects:
Online Access:http://eprints.utem.edu.my/id/eprint/80/
http://eprints.utem.edu.my/id/eprint/80/1/Enhanced_ACF_for_Heterogeneous_log-id_47_camera_ready.pdf
_version_ 1848886882360885248
author Yusof, R.
Selamat, S. R.
Sahib, S.
Mas'ud, M. Z.
Abdollah, M. F.
author_facet Yusof, R.
Selamat, S. R.
Sahib, S.
Mas'ud, M. Z.
Abdollah, M. F.
author_sort Yusof, R.
building UTeM Institutional Repository
collection Online Access
description Management of intrusion alarms particularly in identifying malware attack is becoming more demanding due to large amount of alert produced by low-level detectors. Alert correlation can provide high-level view of intrusion alerts but incapable of handling large amount of alarm. This paper proposes an enhanced Alert Correlation Framework for sensors and heterogeneous log. It can reduce the large amount of false alarm and identify the perspective of the attack. This framework is mainly focusing on the alert correlation module which consists of Alarm Thread Reconstruction, Log Thread Reconstruction, Attack Session Reconstruction, Alarm Merging and Attack Pattern Identification module. It is evaluated using metric for effectiveness that shows high correlation rate, reduction rate, identification rate and low misclassification rate. Meanwhile in statistical validation it has highly significance result with p < 0.05. This enhanced Alert Correlation Framework can be extended into research areas in alert correlation and computer forensic investigation.
first_indexed 2025-11-15T19:45:33Z
format Conference or Workshop Item
id utem-80
institution Universiti Teknikal Malaysia Melaka
institution_category Local University
language English
last_indexed 2025-11-15T19:45:33Z
publishDate 2011
recordtype eprints
repository_type Digital Repository
spelling utem-802015-05-28T02:16:40Z http://eprints.utem.edu.my/id/eprint/80/ Enhanced Alert Correlation Framework for Heterogeneous Log Yusof, R. Selamat, S. R. Sahib, S. Mas'ud, M. Z. Abdollah, M. F. Q Science (General) Management of intrusion alarms particularly in identifying malware attack is becoming more demanding due to large amount of alert produced by low-level detectors. Alert correlation can provide high-level view of intrusion alerts but incapable of handling large amount of alarm. This paper proposes an enhanced Alert Correlation Framework for sensors and heterogeneous log. It can reduce the large amount of false alarm and identify the perspective of the attack. This framework is mainly focusing on the alert correlation module which consists of Alarm Thread Reconstruction, Log Thread Reconstruction, Attack Session Reconstruction, Alarm Merging and Attack Pattern Identification module. It is evaluated using metric for effectiveness that shows high correlation rate, reduction rate, identification rate and low misclassification rate. Meanwhile in statistical validation it has highly significance result with p < 0.05. This enhanced Alert Correlation Framework can be extended into research areas in alert correlation and computer forensic investigation. 2011-11-14 Conference or Workshop Item NonPeerReviewed application/pdf en http://eprints.utem.edu.my/id/eprint/80/1/Enhanced_ACF_for_Heterogeneous_log-id_47_camera_ready.pdf Yusof, R. and Selamat, S. R. and Sahib, S. and Mas'ud, M. Z. and Abdollah, M. F. (2011) Enhanced Alert Correlation Framework for Heterogeneous Log. In: The International Conference on Informatics Engineering & Information Science (ICIEIS2011), Nov. 14-16, 2011, University Technology Malaysia, KL Malaysia. (In Press) http://www.sdiwc.net/kl/
spellingShingle Q Science (General)
Yusof, R.
Selamat, S. R.
Sahib, S.
Mas'ud, M. Z.
Abdollah, M. F.
Enhanced Alert Correlation Framework for Heterogeneous Log
title Enhanced Alert Correlation Framework for Heterogeneous Log
title_full Enhanced Alert Correlation Framework for Heterogeneous Log
title_fullStr Enhanced Alert Correlation Framework for Heterogeneous Log
title_full_unstemmed Enhanced Alert Correlation Framework for Heterogeneous Log
title_short Enhanced Alert Correlation Framework for Heterogeneous Log
title_sort enhanced alert correlation framework for heterogeneous log
topic Q Science (General)
url http://eprints.utem.edu.my/id/eprint/80/
http://eprints.utem.edu.my/id/eprint/80/
http://eprints.utem.edu.my/id/eprint/80/1/Enhanced_ACF_for_Heterogeneous_log-id_47_camera_ready.pdf