•  
  •  
 

Journal of System Simulation

Abstract

Abstract: Distributed Intrusion Detection System has created the problem to investigate a mass of duplicate alerts and high false positive rate in practical applications. Based on DBSCAN, density based spatial and temporal clustering of applications with noise (DBS&TCAN) algorithm was proposed by introducing temporal density. The approach aggregated partial alerts based on spatial density, and merges partial aggregation on the basis of temporal density. The effectiveness of the algorithm was demonstrated by the intrusion detection evaluation dataset. The comparative experiments and analysis show that the algorithm is effective in alert aggregation and gives better results in terms of real time.

First Page

1336

Revised Date

2015-07-24

Last Page

1343

CLC

TP393.08

Recommended Citation

Zhang Jing, Wang Hengjun, Li Junquan, Yu Bin. Research of Intrusion Alert Aggregation Based on Spatial and Temporal Density[J]. Journal of System Simulation, 2016, 28(6): 1336-1343.

Share

COinS