Active Learning for Alert Triage

ICMLA), 2013 12th International Conference(2013)

引用 3|浏览4
暂无评分
摘要
In the cyber security operations of a typical organization, data from multiple sources are monitored, and when certain conditions in the data are met, an alert is generated in a Security Event and Incident Management system. Analysts inspect these alerts to decide if any deserve promotion to an event requiring further scrutiny. This triage process is manual, time-consuming, and detracts from the in-depth investigation of events. We investigate the use of supervised machine learning to automatically prioritize these alerts. In particular, we utilize active learning to make efficient use of the pool of unlabeled alerts, thereby improving the performance of our ranking models over passive learning. We demonstrate the effectiveness of active learning on a large, real-world dataset of cyber security alerts.
更多
查看译文
关键词
in-depth investigation,cyber security operation,cyber security,active learning,alert triage,certain condition,efficient use,passive learning,incident management system,multiple source,security event,learning artificial intelligence
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要