On the Use of Different Statistical Tests for Alert Correlation - Short Paper

Abstract

In this paper we analyze the use of different types of statistical tests for the correlation of anomaly detection alerts. We show that the Granger Causality Test, one of the few proposals that can be extended to the anomaly detection domain, strongly depends on good choices of a parameter which proves to be both sensitive and difficult to estimate. We propose a different approach based on a set of simpler statistical tests, and we prove that our criteria work well on a simplified correlation task, without requiring complex configuration parameters.

Publication
Proceedings of the International Symposium on Recent Advances in Intrusion Detection (RAID)