Using Fuzzy System to Manage False Alarms in Intrusion Detection

The Fuzzy Adaptive Survivability Tools (FAST) is an intelligent multiagent based intrusion detection system that survives the network in the face of large scale intrusion problems. The proposed system is based on automated detection and response approach for survivability. It identifies anomalous host and system variables and uses them to detect known attacks and events of interest. The system uses different intelligent agents to identify normal and abnormal patterns automatically and adaptively. Fuzzy logic is used to discover the underlaying structure of normal and misuse patterns. The simulation results obtained with KDD CUP 1999 data set indicates that the proposed system can effectively manage false alarms.