Reference Hub3
An Efficient Intrusion Alerts Miner for Forensics Readiness in High Speed Networks

An Efficient Intrusion Alerts Miner for Forensics Readiness in High Speed Networks

Aymen Akremi, Hassen Sallay, Mohsen Rouached
Copyright: © 2014 |Volume: 8 |Issue: 1 |Pages: 17
ISSN: 1930-1650|EISSN: 1930-1669|EISBN13: 9781466654990|DOI: 10.4018/ijisp.2014010104
Cite Article Cite Article

MLA

Akremi, Aymen, et al. "An Efficient Intrusion Alerts Miner for Forensics Readiness in High Speed Networks." IJISP vol.8, no.1 2014: pp.62-78. http://doi.org/10.4018/ijisp.2014010104

APA

Akremi, A., Sallay, H., & Rouached, M. (2014). An Efficient Intrusion Alerts Miner for Forensics Readiness in High Speed Networks. International Journal of Information Security and Privacy (IJISP), 8(1), 62-78. http://doi.org/10.4018/ijisp.2014010104

Chicago

Akremi, Aymen, Hassen Sallay, and Mohsen Rouached. "An Efficient Intrusion Alerts Miner for Forensics Readiness in High Speed Networks," International Journal of Information Security and Privacy (IJISP) 8, no.1: 62-78. http://doi.org/10.4018/ijisp.2014010104

Export Reference

Mendeley
Favorite Full-Issue Download

Abstract

Intrusion Detection System is considered as a core tool in the collection of forensically relevant evidentiary data in real or near real time from the network. The emergence of High Speed Network (HSN) and Service oriented architecture/Web Services (SOA/WS) putted the IDS in face of a typical big data management problem. The log files that IDS generates are very enormous making very fastidious and both compute and memory intensive the forensics readiness process. Furthermore the high level rate of wrong alerts complicates the forensics expert alert analysis and it disproves its performance, efficiency and ability to select the best relevant evidences to attribute attacks to criminals. In this context, we propose Alert Miner (AM), an intrusion alert classifier, which classifies efficiently in near real-time the intrusion alerts in HSN for Web services. AM uses an outlier detection technique based on an adaptive deduced association rules set to classify the alerts automatically and without human assistance. AM reduces false positive alerts without losing high sensitivity (up to 95%) and accuracy up to (97%). Therefore AM facilitates the alert analysis process and allows the investigators to focus their analysis on the most critical alerts on near real-time scale and to postpone less critical alerts for an off-line log analysis.

Request Access

You do not own this content. Please login to recommend this title to your institution's librarian or purchase it from the IGI Global bookstore.