DATE: Thursday, Oct. 21, 2004
TIME: 1:30 pm
PLACE: Council Room (SITE 5-084)
TITLE: Communication Network Event Correlation Using the Autoassociator
PRESENTER: Reuben Smith
University of Ottawa
ABSTRACT:

Network event correlation is the process where correlations between network events are discovered and reported. Network intrusion detection analysts who have capable event correlation software at their disposal are more effective because the software can give an intrusion analyst a broader view of the threats posed to their system. The event correlation information is used by a network administrator to deduce the true relationship between individual network events. The autoassociator is ideally suited to the task of network event correlation. The autoassociator is a specialized piece of neural network architecture that can be used to cluster numerically similar data instances. We use the autoassociator to build prototype software to cluster network alerts generated by a Snort intrusion detection system, and discuss how the results are significant, and how they can be applied to other types of network events.