dc.contributor.author |
Mansour, Nashat |
|
dc.contributor.author |
Faour, Ahmad |
|
dc.contributor.author |
Shehab, Maya |
|
dc.date.accessioned |
2018-05-18T12:03:10Z |
|
dc.date.available |
2018-05-18T12:03:10Z |
|
dc.date.copyright |
2008 |
en_US |
dc.date.issued |
2018-05-18 |
|
dc.identifier.uri |
http://hdl.handle.net/10725/7860 |
|
dc.description.abstract |
A Network Intrusion Detection System (NIDS) monitors all network actions and generates alarms when it detects suspicious attempts. We present a data mining technique to assist network administrators to analyze and reduce false positive alarms that are produced by a NIDS. Our data mining technique is based on a Growing Hierarchical Self-Organizing Map (GHSOM) that adjusts its architecture during an unsupervised training process according to the characteristics of the input alarm data. GHSOM clusters these alarms in a way that supports network administrators in making decisions about true and false alarms. Our empirical results show that our technique is useful for real-world intrusion data. |
en_US |
dc.language.iso |
en |
en_US |
dc.publisher |
IEEE Xplore |
en_US |
dc.title |
Growing hierarchical self-organizing map for filtering intrusion detection alarms |
en_US |
dc.type |
Conference Paper / Proceeding |
en_US |
dc.author.school |
SAS |
en_US |
dc.author.idnumber |
198629170 |
en_US |
dc.author.department |
Computer Science and Mathematics |
en_US |
dc.description.embargo |
N/A |
en_US |
dc.keywords |
Self-organizing map |
en_US |
dc.keywords |
Alarm filtering |
en_US |
dc.keywords |
Computer security |
en_US |
dc.keywords |
Growing hierarchical self-organizing |
en_US |
dc.keywords |
Map |
en_US |
dc.keywords |
Intrusion detection |
en_US |
dc.identifier.doi |
http://dx.doi.org/10.1109/I-SPAN.2008.42 |
en_US |
dc.identifier.ctation |
Shehab, M., Mansour, N., & Faour, A. (2008, May). Growing hierarchical self-organizing map for filtering intrusion detection alarms. In Parallel Architectures, Algorithms, and Networks, 2008. I-SPAN 2008. International Symposium on (pp. 167-172). IEEE. |
en_US |
dc.author.email |
nmansour@lau.edu.lb |
en_US |
dc.conference.date |
7-9 May 2008 |
en_US |
dc.conference.place |
Sydney, NSW, Australia |
en_US |
dc.conference.title |
International Symposium on Parallel Architectures, Algorithms, and Networks, 2008 (I-SPAN 2008) |
en_US |
dc.identifier.tou |
http://libraries.lau.edu.lb/research/laur/terms-of-use/articles.php |
en_US |
dc.identifier.url |
https://ieeexplore.ieee.org/abstract/document/4520211/ |
en_US |
dc.orcid.id |
https://orcid.org/0000-0002-3603-8284 |
en_US |
dc.author.affiliation |
Lebanese American University |
en_US |