Intrusion detection alarms reduction using root cause analysis and clustering.
Safaa O. Al-MamoryHongli ZhangPublished in: Comput. Commun. (2009)
Keyphrases
- intrusion detection
- root cause analysis
- anomaly detection
- intrusion detection system
- network intrusion detection
- network security
- clustering algorithm
- network traffic
- high detection rate
- detecting anomalous
- artificial immune
- information security
- data mining
- computer security
- root cause
- computer networks
- decision support
- cyber security
- k means
- network intrusion
- unsupervised learning
- intrusion prevention
- false positives and false negatives
- information systems
- alert correlation
- false alarms
- network intrusions
- decision making
- distributed intrusion detection