Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2007

Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems

Résumé

It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. This paper presents a new approach for handling intrusion detection alarms more efficiently. Neural Network analyses based on the self-organizing map (SOM) and the growing hierarchical self-organizing map (GHSOM) are used to discover interrest patterns signs of potential scenarios of attacks aiming each machine in the network. The GHSOM addresses two main limits of SOM which are caused, on the one hand, by the static architecture of this model, as well as, on the other hand, by the limited capabilities for the representation of hierarchical relations of the data. The experiments conducted on several logs extracted from the SNORT NIDS, confirm that the GHSOM can form an adaptive architecture, which grows in size and depth during its training process, thus to unfold the hierarchical structure of the analyzed logs of alerts.
Fichier principal
Vignette du fichier
ntms07-1.pdf (148.24 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-00412943 , version 1 (17-04-2020)

Identifiants

Citer

Ahmad Faour, Philippe Leray, Bassam Eter. Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems. NTMS'07, 2007, Paris, France. pp.CDROM, ⟨10.1007/978-1-4020-6270-4_58⟩. ⟨hal-00412943⟩
88 Consultations
95 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More