VEGAS: Visualizing, exploring and grouping alerts - Archive ouverte HAL Accéder directement au contenu
Communication Dans Un Congrès Année : 2016

VEGAS: Visualizing, exploring and grouping alerts

Résumé

The large quantities of alerts generated by intrusion detection systems (IDS) make very difficult to distinguish on a network real threats from noise. To help solving this problem, we propose VEGAS, an alerts visualization and classification tool that allows first line security operators to group alerts visually based on their principal component analysis (PCA) representation. VEGAS is included in a workflow in such a way that once a set of similar alerts has been collected and diagnosed, a filter is generated that redirects forthcoming similar alerts to other security analysts that are specifically in charge of this set of alerts, in effect reducing the flow of raw undiagnosed alerts.
Fichier principal
Vignette du fichier
paper.pdf (142.39 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01416464 , version 1 (14-12-2016)

Identifiants

Citer

Damien Crémilleux, Christophe Bidan, Frédéric Majorczyk, Nicolas Prigent. VEGAS: Visualizing, exploring and grouping alerts. IEEE/IFIP International Workshop on Analytics for Network and Service Management, Apr 2016, Istanbul, Turkey. pp.1097 - 1100, ⟨10.1109/NOMS.2016.7502968⟩. ⟨hal-01416464⟩
436 Consultations
284 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More