Clustering of Snort alerts to identify patterns and reduce analyst workload.
Richard E. HarangPeter GuarinoPublished in: MILCOM (2012)
Keyphrases
- intrusion detection system
- previously unknown
- similar patterns
- clustering algorithm
- clustering method
- network intrusion detection
- k means
- hierarchical clustering
- intrusion detection
- multiple data streams
- data clustering
- decision support
- pattern discovery
- distance metric
- data analysis
- cluster analysis
- network security
- maintenance cost
- pattern mining
- self organizing maps
- unsupervised learning
- data points
- document clustering
- data mining
- information theoretic
- similarity function
- design patterns
- outlier detection
- categorical data
- graph theoretic
- clustering analysis
- response time
- database systems
- website