
Evaluating the Robustness of Attack Signatures for Alert Correlation
Intrusion Detection Systems (IDS) are efficient solutions that enable cyber attacks to be detected in hosts and networks. As cyber attacks are developing rapidly, anomaly-based IDS systems in particular offer many advantages, but also disadvantages, including alert flooding. Therefore the sequential step of alert correlation is necessary to reduce the number of alerts and to provide previously unseen attacks with important contextual information for further operator analysis. This paper investigates how robust attack signatures - representatives derived from the communication structure of alert clusters - are for known and unknown attacks. For this purpose, the publicly available datasets CIDDS-001, CIDDS-002 and CIC-IDS2017 were used, which share common but also different attack categories and were recorded at different times and in different networks. In the case of the comparison CIDDS-001/CIDDS-002, an accuracy of 85% for attack category assignment based on signatures was achieved, while the combination CIC-IDS2017/CIDDS-001 was only accurate in 27% of assignments.
You may also find the article on the publisher's website.
Keywords: Intrusion Detection Systems; Network Security; Alert Correlation; Attack Signatures
Year: 2026
Full text [1001 kB]Authors of this publication:

Michael Heigl
E-mail: heigl@kiv.zcu.cz

Dalibor Fiala
Phone: +420 377 63 2429
E-mail: dalfia@kiv.zcu.cz
WWW: http://www.kiv.zcu.cz/~dalfia/
