Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems - LINA - Equipe Connaissances, Optimisation, Décision
Conference Papers Year : 2007

Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems

Abstract

It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. This paper presents a new approach for handling intrusion detection alarms more efficiently. Neural Network analyses based on the self-organizing map (SOM) and the growing hierarchical self-organizing map (GHSOM) are used to discover interrest patterns signs of potential scenarios of attacks aiming each machine in the network. The GHSOM addresses two main limits of SOM which are caused, on the one hand, by the static architecture of this model, as well as, on the other hand, by the limited capabilities for the representation of hierarchical relations of the data. The experiments conducted on several logs extracted from the SNORT NIDS, confirm that the GHSOM can form an adaptive architecture, which grows in size and depth during its training process, thus to unfold the hierarchical structure of the analyzed logs of alerts.
Fichier principal
Vignette du fichier
ntms07-1.pdf (148.24 Ko) Télécharger le fichier
Origin Files produced by the author(s)
Loading...

Dates and versions

hal-00412943 , version 1 (17-04-2020)

Identifiers

Cite

Ahmad Faour, Philippe Leray, Bassam Eter. Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems. NTMS'07, 2007, Paris, France. pp.CDROM, ⟨10.1007/978-1-4020-6270-4_58⟩. ⟨hal-00412943⟩
169 View
124 Download

Altmetric

Share

More