作者
Andrea Paudice, Santonu Sarkar, Domenico Cotroneo
发表日期
2014/11
研讨会论文
Software Reliability Engineering Workshops (ISSREW), 2014 IEEE International Symposium on
页码范围
335-340
出版商
IEEE
简介
In response to attack against corporative and enterprise networks, administrators deploy intrusion detection systems, monitors, vulnerability scans and log systems. These systems monitor and record host and network device activities searching for signs of anomalies and security incidents. Doing that, these systems generally produce a huge number of alerts that overwhelms security analysts. This paper proposes the application of a conceptual clustering technique for filtering alerts and shows the results obtained for seven months of security alerts generated in a real large scale SaaS Cloud system. The technique has been useful to support manual analysis activities conducted by the operations team of the reference Cloud system.
引用总数
201620172018201920202021202220232024125557152
学术搜索中的文章
A Paudice, S Sarkar, D Cotroneo - 2014 IEEE International Symposium on Software …, 2014