发明名称 Probabilistic alert correlation
摘要 This invention uses probabilistic correlation techniques to increase sensitivity, reduce false alarms, and improve alert report quality in intrusion detection systems. In one preferred embodiment, an intrusion detection system includes at least two sensors to monitor different aspects of a computer network, such as a sensor that monitors network traffic and a sensor that discovers and monitors available network resources. The sensors are correlated in that the belief state of one sensor is used to update or modify the belief state of another sensor. In another embodiment of this invention, probabilistic correlation techniques are used to organize alerts generated by different sensors in an intrusion detection system. By comparing features of each new alert with features of previous alerts, rejecting a match if a feature fails to meet or exceed a minimum similarity value, and adjusting the comparison by an expectation that certain feature values will or will not match, the alerts can be grouped in an intelligent manner.
申请公布号 US2002059078(A1) 申请公布日期 2002.05.16
申请号 US20010944788 申请日期 2001.08.31
申请人 VALDES ALFONSO DE JESUS;SKINNER KEITH 发明人 VALDES ALFONSO DE JESUS;SKINNER KEITH
分类号 H04L12/24;H04L29/06;(IPC1-7):G06F17/60 主分类号 H04L12/24
代理机构 代理人
主权项
地址