Automated False Positive Filtering for esNetwork Alerts

08/26/2022
by   Guangyi Zhu, et al.
0

An Intrusion Detection System (IDS) is one of the security tools that can automatically analyze network traffic and detect suspicious activities. They are widely implemented as security guarantee tools in various business networks. However, the high rate of false-positive alerts creates an overwhelming number of unnecessary alerts for security analysts to sift through. The esNetwork is an IDS product by eSentire Inc. This project focuses on reducing the false-positive alerts generated by esNetwork with the help of a Random Forest (RF) classifier. The RF model was built to classify the alerts as high and low and only pass high likelihood alerts to the analysts. As a result of evaluation experiments, this model can achieve an accuracy of 97 training validation, 88 Security Operation Centre (SOC) reviewed events. The evaluation result of the proposed model is intermediate because of the deficiency of clearly labeled data for training as well as the SOC-reviewed events for evaluation. The model still needs time to be fine-tuned to meet the industry deployment requirement.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/08/2018

Evaluation of Machine Learning Algorithms for Intrusion Detection System

Intrusion detection system (IDS) is one of the implemented solutions aga...
research
12/29/2017

A Deep Belief Network Based Machine Learning System for Risky Host Detection

To assure cyber security of an enterprise, typically SIEM (Security Info...
research
03/01/2020

Securing of Unmanned Aerial Systems (UAS) against security threats using human immune system

UASs form a large part of the fighting ability of the advanced military ...
research
09/28/2022

Anomaly detection optimization using big data and deep learning to reduce false-positive

Anomaly-based Intrusion Detection System (IDS) has been a hot research t...
research
06/12/2019

An Effective Payload Attribution Scheme for Cybercriminal Detection Using Compressed Bitmap Index Tables and Traffic Downsampling

Payload attribution systems (PAS) are one of the most important tools of...
research
07/23/2021

Automatic Detection Of Noise Events at Shooting Range Using Machine Learning

Outdoor shooting ranges are subject to noise regulations from local and ...
research
06/14/2020

A Neural Network Approach for Online Nonlinear Neyman-Pearson Classification

We propose a novel Neyman-Pearson (NP) classifier that is both online an...

Please sign up or login with your details

Forgot password? Click here to reset