Beta
33007

Towards Implementing Agent Based Correlation Model For Real-Time Intrusion Detection Alerts

Article

Last updated: 04 Jan 2025

Subjects

-

Tags

-

Abstract

Abstract:
Alert correlation is a promising technique in intrusion detection. It analyzes the alerts
from one or more intrusion detection system and provides a compact summarized
report and high-level view of attempted intrusions which highly improves security
effectiveness. Correlation component is a procedure which aggregates alerts
according to certain criteria. The aggregated alerts could have common features or
represent steps of pre-defined scenario attacks. Correlation approaches composed of
a single component or a comprehensive set of components. The effectiveness of a
component depends heavily on the nature of the real alerts or the dataset analyzed.
The order of correlation components affects the correlation process performance.
Moreover not all components should be used for different dataset. This paper
presents implementation of an Agent Based Correlation Model for real-time intrusion
detection alerts. Learning agent learns the nature of alerts within a network then
guides the whole correlation process and components in such a suitable way of which
components could be used and in which order. The model improves the performance
of correlation process by selecting the proper components to be used. The simulation
results showed that ABCM model assures minimum alerts to be processed on each
component depending on the dataset and minimum time for correlation process.

DOI

10.21608/iceeng.2010.33007

Keywords

Alert Correlation, Intrusion Detection, Learning Agent, Agent-Based Systems

Authors

First Name

Ismail

Last Name

Abdel Ghafar

MiddleName

-

Affiliation

Egyptian Armed Forces.

Email

-

City

-

Orcid

-

First Name

Ayman

Last Name

Taha

MiddleName

E.

Affiliation

Egyptian Armed Forces.

Email

-

City

-

Orcid

-

First Name

Ayman

Last Name

Bahaa Eldin

MiddleName

M.

Affiliation

Computer and Systems Engineering Department, College of Engineering, Ain Shams University, Abasia, Cairo, Egypt.

Email

-

City

-

Orcid

-

First Name

Hani

Last Name

Mahdi

MiddleName

M. K.

Affiliation

Computer and Systems Engineering Department, College of Engineering, Ain Shams University, Abasia, Cairo, Egypt.

Email

-

City

-

Orcid

-

Volume

7

Article Issue

7th International Conference on Electrical Engineering ICEENG 2010

Related Issue

5537

Issue Date

2010-05-01

Receive Date

2019-05-23

Publish Date

2010-05-01

Page Start

1

Page End

13

Print ISSN

2636-4433

Online ISSN

2636-4441

Link

https://iceeng.journals.ekb.eg/article_33007.html

Detail API

https://iceeng.journals.ekb.eg/service?article_code=33007

Order

48

Type

Original Article

Type Code

833

Publication Type

Journal

Publication Title

The International Conference on Electrical Engineering

Publication Link

https://iceeng.journals.ekb.eg/

MainTitle

Towards Implementing Agent Based Correlation Model For Real-Time Intrusion Detection Alerts

Details

Type

Article

Created At

22 Jan 2023