PASCAL - Pattern Analysis, Statistical Modelling and Computational Learning

Growing hierarchical self-organizing map for alarm filtering in network intrusion detection systems
A. Faour, Philippe Leray and B. Eter
In: The 2007 International conference on New Technologes, Mobility and Security (NTMS'2007), 2-4 may 2007, Paris, France.

Abstract

It is a well-known problem that intrusion detection systems overload their human operators by triggering thousands of alarms per day. This paper presents a new approach for handling intrusion detection alarms more efficiently. Neural Network analyses based on the self-organizing map (SOM) and the growing hierarchical self-organizing map (GHSOM) are used to discover interrest patterns signs of potential scenarios of attacks aiming each machine in the network. The GHSOM addresses two main limits of SOM which are caused, on the one hand, by the static architecture of this model, as well as, on the other hand, by the limited capabilities for the representation of hierarchical relations of the data. The experiments conducted on several logs extracted from the SNORT NIDS, confirm that the GHSOM can form an adaptive architecture, which grows in size and depth during its training process, thus to unfold the hierarchical structure of the analyzed logs of alerts.

EPrint Type:Conference or Workshop Item (Paper)
Project Keyword:Project Keyword UNSPECIFIED
Subjects:Learning/Statistics & Optimisation
ID Code:3769
Deposited By:Philippe Leray
Deposited On:21 February 2008