作者: Ali A. Ghorbani , Wei Lu , Mahbod Tavallaee
DOI: 10.1007/978-0-387-88771-5_6
关键词:
摘要: Alert management includes functions to cluster, merge and correlate alerts. The clustering merging recognize alerts that correspond the same occurrence of an attack create a new alert merges data contained in these various correlation function can relate different build big picture attack. correlated also be used for cooperative intrusion detection tracing its source.