Distributed Intrusion Alert Fusion Based on Multi Keyword

Intrusion alert fusion is a key problem in distributed intrusion detection system (DIDS). In this paper, we propose a distributed intrusion alert fusion scheme based on Multi Keywords. All the related alarms produced by local sensor can be evenly routed and fused to its corresponding sensor fusion centers (SFCs) by multi keywords, while evenly distributing unrelated alarms to different SFCs. We use DShield data collected from worldwide providers to evaluate feasibility of our scheme.