Unsupervised Approach for Post-processing of Intrusion Detection Alerts.

Show simple item record

dc.contributor.author Kumarasinghe, K.
dc.contributor.author Kumarasiri, M.
dc.contributor.author Kumarasinghe, T.
dc.contributor.author Liyanage, K.S.K.
dc.contributor.author Manawadu, Y.
dc.contributor.author Mamankaran, H.
dc.date.accessioned 2025-07-04T09:59:25Z
dc.date.available 2025-07-04T09:59:25Z
dc.date.issued 2025-06-04
dc.identifier.citation Kumarasinghe, K., Kumarasiri, M., Kumarasinghe, T., Liyanage, K. S. K., Manawadu, Y. & Mamankaran, H. (2025). nsupervised Approach for Post-processing of Intrusion Detection Alerts. 22nd Academic Sessions & Vice – Chancellor’s Awards, Faculty of Agriculture, University of Ruhuna, Sri Lanka. 61. en_US
dc.identifier.issn 2362-0412
dc.identifier.uri http://ir.lib.ruh.ac.lk/handle/iruor/19733
dc.description.abstract Intrusion Detection Systems (IDS) play a critical role in network security, monitoring and identifying suspicious activities to prevent potential threats. However, the overwhelming volume of alerts and high false-positive rates frequently limit their efficacy, making it difficult for security analysts to manage and evaluate the data effectively. Because of these constraints, new approaches are required to improve warning processing and guarantee efficient intrusion detection. Using pattern mining and clustering approaches, this research suggests a unique unsupervised method for post-processing IDS signals. The suggested approach analyzes huge datasets and finds correlations between alerts to eliminate repetition and highlight important patterns. Using agglomerative clustering and the CHARM algorithm for pattern mining, this method efficiently clusters related alarm patterns, providing security analysts with a unified picture of network intrusions. The methodology employs advanced data pre-processing techniques, including adaptive binning, to ensure meaningful and interpretable results. Integrating these techniques simplifies complex alert data, helping analysts focus on actionable insights rather than sifting through noisy information. The proposed system minimises false positives and enhances the detection of diverse cyber threats, such as DDoS, Brute Force, and Botnet attacks, by organising alerts into well-defined clusters. Evaluations demonstrate that this approach significantly reduces analysts' workload while enhancing intrusion detection accuracy. Comparative analyses show that the proposed method outperforms traditional alert management techniques in efficiency and precision. These findings underline the potential of pattern mining and clustering in improving IDS performance. en_US
dc.language.iso en en_US
dc.publisher Faculty of Agriculture, University of Ruhuna, Sri Lanka. en_US
dc.subject Alert processing en_US
dc.subject Clustering en_US
dc.subject Intrusion Detection System en_US
dc.subject Network security en_US
dc.subject Pattern mining en_US
dc.title Unsupervised Approach for Post-processing of Intrusion Detection Alerts. en_US
dc.type Article en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search DSpace


Advanced Search

Browse

My Account