Evaluating the Robustness of Attack Signatures for Alert Correlation

Evaluating the Robustness of Attack Signatures for Alert Correlation

Intrusion Detection Systems (IDS) are efficient solutions that enable cyber attacks to be detected in hosts and networks. As cyber attacks are developing rapidly, anomaly-based IDS systems in particular offer many advantages, but also disadvantages, including alert flooding. Therefore the sequential step of alert correlation is necessary to reduce the number of alerts and to provide previously unseen attacks with important contextual information for further operator analysis. This paper investigates how robust attack signatures - representatives derived from the communication structure of alert clusters - are for known and unknown attacks. For this purpose, the publicly available datasets CIDDS-001, CIDDS-002 and CIC-IDS2017 were used, which share common but also different attack categories and were recorded at different times and in different networks. In the case of the comparison CIDDS-001/CIDDS-002, an accuracy of 85% for attack category assignment based on signatures was achieved, while the combination CIC-IDS2017/CIDDS-001 was only accurate in 27% of assignments.

You may also find the article on the publisher's website.

Keywords: Intrusion Detection Systems; Network Security; Alert Correlation; Attack Signatures

Year: 2026

Download: download Full text [1001 kB]

Authors of this publication:


Michael Heigl


E-mail: heigl@kiv.zcu.cz

Michael is currently working as a research associate at the institute ProtectIT at the Deggendorf Institute of Technology and holds a Ph.D. degree from the University of West Bohemia for his dissertation on machine learning enhanced network-based anomaly detection. He is specialized in improving outlier detection methods for streaming data applications.

Dalibor Fiala


Phone: +420 377 63 2429
E-mail: dalfia@kiv.zcu.cz
WWW: http://www.kiv.zcu.cz/~dalfia/

Dalibor is the former research group coordinator, an analyst with CCA Group a.s., and an associate professor at the Department of Computer Science and Engineering at the University of West Bohemia in Pilsen, Czech Republic. He is interested in data mining, web mining, information retrieval, informetrics, and information science.