发明名称 METHOD AND SYSTEM FOR ALERT CLASSIFICATION IN A COMPUTER NETWORK
摘要 A method and a system for classification of intrusion alerts in computer network is provided. The method comprises the steps of monitoring traffic data in a computer network, detecting an intrusion, providing an intrusion alert and data in relation to the intrusion alert, generating a statistical analysis of the data in relation to the intrusion alert and classifying the intrusion alert based on said statistical analysis. The intrusion alerts and the data in relation to an intrusion alert may be generated by anomaly-based intrusion detection system. The generating a statistical analysis may comprise generating information about a statistical distribution of n-grams in the data. The classification may comprise comparing the statistical analysis with a model analysis of intrusion alerts with predefined alert classes. This model may be generated by providing a training set of data in relation to alerts, generating a model statistical analysis of said data, predefining at least two alert classes, and assigning predefined alert classes to the statistical analysis, based on information provided by a signature-based intrusion detection system, or by a human operator.
申请公布号 US2012036577(A1) 申请公布日期 2012.02.09
申请号 US201013262112 申请日期 2010.03.31
申请人 BOLZONI DAMIANO;ETALLE SANDRO;SECURITY MATTERS B.V. 发明人 BOLZONI DAMIANO;ETALLE SANDRO
分类号 G06F21/00;G06F11/30 主分类号 G06F21/00
代理机构 代理人
主权项
地址