{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T14:20:55Z","timestamp":1761402055206,"version":"build-2065373602"},"reference-count":51,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2020,3,12]],"date-time":"2020-03-12T00:00:00Z","timestamp":1583971200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Key R&amp;D Program of China","award":["No. 2017YFB080301"],"award-info":[{"award-number":["No. 2017YFB080301"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>With the emergence of network security issues, various security devices that generate a large number of logs and alerts are widely used. This paper proposes an alert aggregation scheme that is based on conditional rough entropy and knowledge granularity to solve the problem of repetitive and redundant alert information in network security devices. Firstly, we use conditional rough entropy and knowledge granularity to determine the attribute weights. This method can determine the different important attributes and their weights for different types of attacks. We can calculate the similarity value of two alerts by weighting based on the results of attribute weighting. Subsequently, the sliding time window method is used to aggregate the alerts whose similarity value is larger than a threshold, which is set to reduce the redundant alerts. Finally, the proposed scheme is applied to the CIC-IDS 2018 dataset and the DARPA 98 dataset. The experimental results show that this method can effectively reduce the redundant alerts and improve the efficiency of data processing, thus providing accurate and concise data for the next stage of alert fusion and analysis.<\/jats:p>","DOI":"10.3390\/e22030324","type":"journal-article","created":{"date-parts":[[2020,3,12]],"date-time":"2020-03-12T12:22:51Z","timestamp":1584015771000},"page":"324","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":12,"title":["An Efficient Alert Aggregation Method Based on Conditional Rough Entropy and Knowledge Granularity"],"prefix":"10.3390","volume":"22","author":[{"given":"Jiaxuan","family":"Sun","sequence":"first","affiliation":[{"name":"Institute of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lize","family":"Gu","sequence":"additional","affiliation":[{"name":"Institute of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaiyuan","family":"Chen","sequence":"additional","affiliation":[{"name":"Institute of Cyberspace Security, Beijing University of Posts and Telecommunications, Beijing 100876, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,3,12]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Chandola, V., Banerjee, A., and Kumar, V. (2009). Anomaly Detection: A Survey. Acm. Comput. Surv., 41.","DOI":"10.1145\/1541880.1541882"},{"key":"ref_2","unstructured":"Lindqvist, U., and Porras, P.A. (1999, January 14). Detecting computer and network misuse through the production-based expert system toolset (P-BEST). Proceedings of the 1999 IEEE Symposium on Security and Privacy (Cat. No. 99CB36344), Oakland, CA, USA."},{"key":"ref_3","unstructured":"Marchette, D.J. (1999, January 9\u201312). A statistical method for profiling network traffic. Proceedings of the Workshop on Intrusion Detection and Network Monitoring, Santa Clara, CA, USA."},{"key":"ref_4","first-page":"1","article-title":"Host-based intrusion detection system with system calls: Review and future trends","volume":"51","author":"Liu","year":"2018","journal-title":"Acm. Comput. Surv."},{"key":"ref_5","unstructured":"Axelsson, S. (1998). Research in Intrusion-Detection Systems: A Survey, Chalmers University of Technology. Technical Report 98\u201317."},{"key":"ref_6","first-page":"8","article-title":"Alert correlation with abstract incident modeling in a multi-sensor environment","volume":"7","author":"Siraj","year":"2007","journal-title":"Int. J. Comput. Sci."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1145\/996943.996947","article-title":"Techniques and tools for analyzing intrusion alerts","volume":"7","author":"Ning","year":"2004","journal-title":"ACM Trans. Inf. Syst. Secur."},{"key":"ref_8","unstructured":"Lundin, E., and Jonsson, E. (1999, January 1\u20132). Some practical and fundamental problems with anomaly detection. Proceedings of the NORDSEC\u201999, Kista, Sweden."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Hus\u00e1k, M., \u010cerm\u00e1k, M., La\u0161tovi\u010dka, M., and Vykopal, J. (2017, January 8\u201312). Exchanging security events: Which and how many alerts can we aggregate?. Proceedings of the 2017 IFIP\/IEEE Symposium on Integrated Network and Service Management (IM), Lisbon, Portugal.","DOI":"10.23919\/INM.2017.7987340"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Mu, C., and Shuai, B. (2012, January 23\u201326). Research on preprocessing technique of alert aggregation. Proceedings of the 2012 Fifth International Joint Conference on Computational Sciences and Optimization, Harbin, China.","DOI":"10.1109\/CSO.2012.136"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"4349","DOI":"10.1016\/j.asoc.2010.12.004","article-title":"Alert correlation in collaborative intelligent intrusion detection systems\u2014A survey","volume":"11","author":"Elshoush","year":"2011","journal-title":"Appl. Soft Comput."},{"key":"ref_12","unstructured":"Cuppens, F. (2001, January 10\u201314). Managing alerts in a multi-intrusion detection environment. Proceedings of the Seventeenth Annual Computer Security Applications Conference, New Orleans, LA, USA."},{"key":"ref_13","unstructured":"Cuppens, F., and Miege, A. (2002, January 12\u201315). Alert correlation in a cooperative intrusion detection framework. Proceedings of the 2002 IEEE symposium on security and privacy, Berkeley, CA, USA."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Huang, S., and Wang, Y. (2012, January 23\u201325). IDS alert classification model construction using decision support techniques. Proceedings of the 2012 International Conference on Computer Science and Electronics Engineering, Hangzhou, China.","DOI":"10.1109\/ICCSEE.2012.242"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Hu, H., Liu, Y., Yang, Y., Zhang, H., and Zhang, Y. (2018). New insights into approaches to evaluating intention and path for network multistep attacks. Math. Probl. Eng., 2018.","DOI":"10.1155\/2018\/4278632"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Hu, H., Zhang, H., Liu, Y., and Wang, Y. (2017). Quantitative method for network security situation based on attack prediction. Secur. Commun. Netw., 2017.","DOI":"10.1155\/2017\/3407642"},{"key":"ref_17","first-page":"1","article-title":"Alert correlation and aggregation techniques for reduction of security alerts and detection of multistage attack","volume":"5","author":"Alserhani","year":"2016","journal-title":"Int. J. Adv. Stud. Comput. Sci. Eng."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Zhang, D., Qian, K., Zhang, P., Mao, S., and Wu, H. (2017, January 26\u201328). Alert correlation analysis based on attack path graph. Proceedings of the 2017 IEEE Conference on Energy Internet and Energy System Integration (EI2), Beijing, China.","DOI":"10.1109\/EI2.2017.8245631"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Hostiadi, D.P., Susila, M.D., and Huizen, R.R. (2019, January 22\u201323). A new alert correlation model based on similarity approach. Proceedings of the 2019 1st International Conference on Cybernetics and Intelligent System (ICORIS), Denpasar, Bali, Indonesia.","DOI":"10.1109\/ICORIS.2019.8874899"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"820","DOI":"10.1016\/j.promfg.2019.06.197","article-title":"Alert correlation for cyber-manufacturing intrusion detection","volume":"34","author":"Wu","year":"2019","journal-title":"Procedia Manuf."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"150540","DOI":"10.1109\/ACCESS.2019.2946261","article-title":"An intrusion action-based ids alert correlation analysis and prediction framework","volume":"7","author":"Zhang","year":"2019","journal-title":"IEEE Access"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Zhang, H., Jin, X., Li, Y., Jiang, Z., Liang, Y., Jin, Z., and Wen, Q. (2019). A multi-step attack detection model based on alerts of smart grid monitoring system. IEEE Access.","DOI":"10.1109\/ACCESS.2019.2961517"},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"206","DOI":"10.1016\/j.cose.2014.10.006","article-title":"RTECA: Real time episode correlation algorithm for multi-step attack scenarios detection","volume":"49","author":"Ramaki","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Wang, T., Zhang, C., Lu, Z., Du, D., and Han, Y. (2019, January 9\u201312). Identifying truly suspicious events and false alarms based on alert graph. Proceedings of the 2019 IEEE International Conference on Big Data (Big Data), Los Angeles, CA, USA.","DOI":"10.1109\/BigData47090.2019.9006555"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1007\/3-540-39945-3_6","article-title":"Adaptive, model-based monitoring for cyber attack detection","volume":"1907","author":"Valdes","year":"2000","journal-title":"Lect. Notes Comput. Sci."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Valdes, A., and Skinner, K. (2001, January 10\u201312). Probabilistic alert correlation. Proceedings of the International Workshop on Recent Advances in Intrusion Detection, Davis, CA, USA.","DOI":"10.1007\/3-540-45474-8_4"},{"key":"ref_27","first-page":"443","article-title":"Clustering intrusion detection alarms to support root cause analysis","volume":"6","author":"Julisch","year":"2003","journal-title":"ACM Trans. Inf."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Long, C., Shen, H., Li, J., and Ge, J. (2014, January 28\u201330). An SR-ISODATA algorithm for IDS alerts aggregation. Proceedings of the 2014 IEEE International Conference on Information and Automation (ICIA), Hailar, China.","DOI":"10.1109\/ICInfA.2014.6932632"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"25","DOI":"10.3991\/ijoe.v12i08.5958","article-title":"An alert fusion method based on grey relation and attribute similarity correlation","volume":"12","author":"Liang","year":"2016","journal-title":"Int. J. Online"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1016\/j.neucom.2015.12.127","article-title":"Multi-source alert data understanding for security semantic discovery based on rough set theory","volume":"208","author":"Yao","year":"2016","journal-title":"Neurocomputing"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Zhang, R., Guo, T., and Liu, J. (2017, January 28\u201329). An IDS alerts aggregation algorithm based on rough set theory. Proceedings of the IOP Conference Series: Materials Science and Engineering, Shanghai, China.","DOI":"10.1088\/1757-899X\/322\/6\/062009"},{"key":"ref_32","first-page":"341","article-title":"Rough sets","volume":"11","author":"Pawlak","year":"1982","journal-title":"Int. J. Comput."},{"key":"ref_33","unstructured":"Komorowski, J., Pawlak, Z., Polkowski, L., and Skowron, A. (1999). Rough sets: A tutorial. Rough Fuzzy Hybridization: A New Trend in Decision-Making, Springer."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"287","DOI":"10.1111\/1468-0394.00253","article-title":"Probabilistic approaches to rough sets","volume":"20","author":"Yao","year":"2003","journal-title":"Expert Syst."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"105980","DOI":"10.1016\/j.asoc.2019.105980","article-title":"An efficient feature selection based Bayesian and Rough set approach for intrusion detection","volume":"87","author":"Prasad","year":"2020","journal-title":"Appl. Soft Comput."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.ssci.2019.05.004","article-title":"Safety monitoring data classification method based on wireless rough network of neighborhood rough sets","volume":"118","author":"Liu","year":"2019","journal-title":"Safety Sci."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1109\/91.493904","article-title":"Fuzzy logic = computing with words","volume":"4","author":"Zadeh","year":"1996","journal-title":"IEEE Trans. Fuzzy Syst."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"410","DOI":"10.1016\/j.ins.2016.04.009","article-title":"A novel approach to information fusion in multi-source datasets: A granular computing viewpoint","volume":"378","author":"Xu","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"23","DOI":"10.1016\/j.ins.2017.05.003","article-title":"An incremental attribute reduction approach based on knowledge granularity with a multi-granulation view","volume":"411","author":"Jing","year":"2017","journal-title":"Inf. Sci."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Mu, T., Zhang, X., and Mo, Z. (2019). Double-granule conditional-entropies based on three-level granular structures. Entropy, 21.","DOI":"10.3390\/e21070657"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"605","DOI":"10.1109\/TSMCA.2002.804790","article-title":"Relational and directional aspects in the construction of information granules","volume":"32","author":"Pedrycz","year":"2002","journal-title":"IEEE Trans. Syst. Man Cybern. A"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"212","DOI":"10.1109\/3477.990878","article-title":"Granular clustering: A granular signature of data","volume":"32","author":"Pedrycz","year":"2002","journal-title":"Ieee Trans. Syst. Man Cybern. B"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"37","DOI":"10.1142\/S0218488504002631","article-title":"The information entropy, rough entropy and knowledge granulation in rough set theory","volume":"12","author":"Liang","year":"2004","journal-title":"Int. J. Uncertain. Fuzziness Knowl. Based Syst."},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"210","DOI":"10.1016\/j.neucom.2015.05.105","article-title":"Mutual information criterion for feature selection from incomplete data","volume":"168","author":"Qian","year":"2015","journal-title":"Neurocomputing"},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"379","DOI":"10.1002\/j.1538-7305.1948.tb01338.x","article-title":"A mathematical theory of communication","volume":"27","author":"Shannon","year":"1948","journal-title":"Bell Syst. Tech. J."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"185","DOI":"10.1016\/S0020-0255(98)00019-X","article-title":"Information-theoretic measures of uncertainty for rough sets and rough relational databases","volume":"109","author":"Beaubouef","year":"1998","journal-title":"Inf. Sci."},{"key":"ref_47","unstructured":"Pawlak, Z. (2012). Rough Sets: Theoretical Aspects of Reasoning about Data, Springer Science & Business Media."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Sun, L., Xu, J., and Cao, X. (2009, January 23\u201324). Decision table reduction method based on new conditional entropy for rough set theory. Proceedings of the 2009 International Workshop on Intelligent Systems and Applications, Wuhan, China.","DOI":"10.1109\/IWISA.2009.5072803"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"283","DOI":"10.1080\/03081079908935239","article-title":"Measuring uncertainty in rough set theory","volume":"28","author":"Wierman","year":"1999","journal-title":"Int. J. Gen. Syst."},{"key":"ref_50","first-page":"29","article-title":"Comparative analysis of supervised and unsupervised discretization techniques","volume":"2","author":"Dash","year":"2011","journal-title":"Int. J. Adv. Sci. Technol."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Sharafaldin, I., Lashkari, A.H., and Ghorbani, A.A. (2018, January 22\u201324). Toward generating a new intrusion detection dataset and intrusion traffic characterization. Proceedings of the ICISSP, Funchal, Madeira, Portugal.","DOI":"10.5220\/0006639801080116"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/22\/3\/324\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:06:21Z","timestamp":1760173581000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/22\/3\/324"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,12]]},"references-count":51,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2020,3]]}},"alternative-id":["e22030324"],"URL":"https:\/\/doi.org\/10.3390\/e22030324","relation":{},"ISSN":["1099-4300"],"issn-type":[{"type":"electronic","value":"1099-4300"}],"subject":[],"published":{"date-parts":[[2020,3,12]]}}}