Comprehensive approaches of intrusion detection in handling false alarm issue
Tjhai GC
Proceedings of the Third Collaborative Research Symposium on Security, E-learning, Internet and Networking (SEIN 2007), Plymouth, UK, ISBN: 978-1-8410-2173-7, pp53-66, 2007
Intrusion detection is one of the most important tools in computer security. Although the technology has been actively developed for two decades, it is an indisputable fact that the art of detecting an intrusion is still far from perfect. IDS systems tend to generate a large number of false alarms per day, which adds a heavy workload for the administrator responsible in handling the alerts. In this paper, a number of current studies focusing upon the reduction of false alarms are briefly discussed. This paper also critically analyses the approaches implemented by current studies and provides recommendations to improve the performance of IDS in term of its alarm generation.

