Visible to the public A Hybrid Alarm Management Strategy in Signature-Based Intrusion Detection Systems

TitleA Hybrid Alarm Management Strategy in Signature-Based Intrusion Detection Systems
Publication TypeConference Paper
Year of Publication2019
AuthorsCortés, Francisco Muñoz, Gaviria Gómez, Natalia
Conference Name2019 IEEE Colombian Conference on Communications and Computing (COLCOM)
Keywordsalarm correlation techniques, alarm prioritization, Alarm systems, Correlation, cybersecurity defense strategy, Databases, digital signatures, dynamic network context information, event normalizer, false alarm minimization, false alarm reduction, HP Arsight priority formula, hybrid alarm management strategy, Intrusion detection, intrusion detection system, IP networks, Measurement, Minimization, Prelude SIEM, pubcrawl, resilience, Resiliency, Scalability, Sensors, signature based defense, Signature-based IDS, signature-based intrusion detection systems, similarity-based correlation, vulnerability analysis
Abstract

Signature-based Intrusion Detection Systems (IDS) are a key component in the cybersecurity defense strategy for any network being monitored. In order to improve the efficiency of the intrusion detection system and the corresponding mitigation action, it is important to address the problem of false alarms. In this paper, we present a comparative analysis of two approaches that consider the false alarm minimization and alarm correlation techniques. The output of this analysis provides us the elements to propose a parallelizable strategy designed to achieve better results in terms of precision, recall and alarm load reduction in the prioritization of alarms. We use Prelude SIEM as the event normalizer in order to process security events from heterogeneous sensors and to correlate them. The alarms are verified using the dynamic network context information collected from the vulnerability analysis, and they are prioritized using the HP Arsight priority formula. The results show an important reduction in the volume of alerts, together with a high precision in the identification of false alarms.

DOI10.1109/ColComCon.2019.8809121
Citation Keycortes_hybrid_2019