Alert correlation thesis

Alert correlation: Review of the state of the art

Facilitating Alert Correlation Using Resource Trees

Alert correlation

An evolution of the intrusion detection system occurs in alert correlation systems, which take raw alerts from numerous sensors within a network and generate broader situational awareness by combining the individual findings of each sensor into a.

The purpose of this document is to offer a review of the state of the art concerning the emerging field of so-called «alert correlation».

Despite the fact that several recent publications seem to present this domain as a new one, we will show the close connections that exist with another well established one, namely network management and its event correlation approaches.

However, in practice the wide usage of alert correlation is hindered by the privacy concern. In this thesis, we propose the TEIRESIAS protocol, which can ensure the privacy-preserving property during the whole process of sharing and correlating alerts, when incorporated with anonymous communication systems.

thesis, driver data are video segments captured by a camera and the method proposed belongs to the group that uses computer vision to detect driver’s state. There are two main states of a driver, those are alert and drowsy states. definitions for scenario graphs and develop algorithms that generate scenario graphs automatically from finite models.

Part II contains a detailed discussion of. The Meta-Alert Correlation Engine was created to satisfy this objective. This thesis report itself serves two main functions. First it explores the problem domain.

