Jump to content

Alert correlation

From Wikipedia, the free encyclopedia
This is an old revision of this page, as edited by Someone who's wrong on the internet (talk | contribs) at 08:37, 16 March 2023 (Added {{Improve categories}} tag). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

Alert correlation is a type of long analysis. It focuses on the process of clustering alerts (events), generated by NIDS and HIDS computer systems, to form higher-level pieces of information.

Example of simple alert correlation is grouping invalid login attempts to report single incident like "10000 invalid login attempts on host X".

See also