| | | | |
|

An Approach to Sensor Correlation
by Keith Skinner & Alfonso Valdes.
Abstract
We present an approach to intrusion detection (ID) sensor correlation that considers the
problem in three phases: event aggregation, sensor coupling, and meta alert fusion. The
approach is well suited to probabilistically based sensors such as EMERALD eBayes.
We demonstrate the efficacy of the EMERALD alert thread mechanism, the sensor
coupling in eBayes, and a prototype alert fusion capability towards achieving significant
functionality in the field of ID sensor correlation.
Files
|
|
|