Vegas: Visualizing, Exploring And Grouping Alerts

NOMS 2016 - 2016 IEEE/IFIP Network Operations and Management Symposium(2016)

引用 3|浏览50
暂无评分
摘要
The large quantities of alerts generated by intrusion detection systems (IDS) make very difficult to distinguish on a network real threats from noise. To help solving this problem, we propose VEGAS, an alerts visualization and classification tool that allows first line security operators to group alerts visually based on their principal component analysis (PCA) representation. VEGAS is included in a workflow in such a way that once a set of similar alerts has been collected and diagnosed, a filter is generated that redirects forthcoming similar alerts to other security analysts that are specifically in charge of this set of alerts, in effect reducing the flow of raw undiagnosed alerts.
更多
查看译文
关键词
Visualization,Intrusion Detection,CyberSecurity,PCA,Workflow,Teamwork
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要