×

Probabilistic alert correlation

  • US 7,917,393 B2
  • Filed: 08/31/2001
  • Issued: 03/29/2011
  • Est. Priority Date: 09/01/2000
  • Status: Active Grant
First Claim
Patent Images

1. In an intrusion detection system that includes a plurality of sensors that generate alerts when attacks or anomalous incidents are detected, a method for organizing the alerts into alert classes, both the alerts and the alert classes having a plurality of features, the method comprising:

  • (a) receiving a new alert;

    (b) identifying a set of similar features shared by the new alert and one or more existing alert classes;

    (c) updating, using a processor, a threshold similarity requirement for one or more of the similar features;

    (d) updating, using a processor, a similarity expectation for one or more of the similar features;

    (e) comparing, using a processor, the new alert with the one or more existing alert classes, using a similarity measure Sim(X,Y) that expresses a similarity between the new alert and a given one of the one or more existing alert classes, where SIM(X,Y) is defined as;

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×