Loading [MathJax]/extensions/MathMenu.js
Active Learning for Alert Triage | IEEE Conference Publication | IEEE Xplore

Active Learning for Alert Triage


Abstract:

In the cyber security operations of a typical organization, data from multiple sources are monitored, and when certain conditions in the data are met, an alert is generat...Show More

Abstract:

In the cyber security operations of a typical organization, data from multiple sources are monitored, and when certain conditions in the data are met, an alert is generated in a Security Event and Incident Management system. Analysts inspect these alerts to decide if any deserve promotion to an event requiring further scrutiny. This triage process is manual, time-consuming, and detracts from the in-depth investigation of events. We investigate the use of supervised machine learning to automatically prioritize these alerts. In particular, we utilize active learning to make efficient use of the pool of unlabeled alerts, thereby improving the performance of our ranking models over passive learning. We demonstrate the effectiveness of active learning on a large, real-world dataset of cyber security alerts.
Date of Conference: 04-07 December 2013
Date Added to IEEE Xplore: 10 April 2014
Electronic ISBN:978-0-7695-5144-9
Conference Location: Miami, FL, USA

Contact IEEE to Subscribe

References

References is not available for this document.