Even if intrusion detection systems have marginally improved in the past few years, they still face the problem of high false positives rate. In this paper we propose the use of a fuzzy inference system, which filters out false positives, without missing on any of the detected attacks. The design of the system is based on meta-alerts, which carry special information about the nature of alerts. The system has been tested against the DARPA dataset and has exhibited a significant reduction (83%) of false positives.
Published in:
Systems, Signals and Image Processing, 2009. IWSSIP 2009. 16th International Conference on
Date of Conference: 18-20 June 2009