{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T12:34:19Z","timestamp":1783082059859,"version":"3.54.6"},"reference-count":91,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T00:00:00Z","timestamp":1644883200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Network Intrusion Detection Systems (NIDS) are designed to safeguard the security needs of enterprise networks against cyber-attacks. However, NIDS networks suffer from several limitations, such as generating a high volume of low-quality alerts. Moreover, 99% of the alerts produced by NIDSs are false positives. As well, the prediction of future actions of an attacker is one of the most important goals here. The study has reviewed the state-of-the-art cyber-attack prediction based on NIDS Intrusion Alert, its models, and limitations. The taxonomy of intrusion alert correlation (AC) is introduced, which includes similarity-based, statistical-based, knowledge-based, and hybrid-based approaches. Moreover, the classification of alert correlation components was also introduced. Alert Correlation Datasets and future research directions are highlighted. The AC receives raw alerts to identify the association between different alerts, linking each alert to its related contextual information and predicting a forthcoming alert\/attack. It provides a timely, concise, and high-level view of the network security situation. This review can serve as a benchmark for researchers and industries for Network Intrusion Detection Systems\u2019 future progress and development.<\/jats:p>","DOI":"10.3390\/s22041494","type":"journal-article","created":{"date-parts":[[2022,2,15]],"date-time":"2022-02-15T22:44:47Z","timestamp":1644965087000},"page":"1494","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":66,"title":["Cyber-Attack Prediction Based on Network Intrusion Detection Systems for Alert Correlation Techniques: A Survey"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4208-2473","authenticated-orcid":false,"given":"Hashim","family":"Albasheer","sequence":"first","affiliation":[{"name":"School of Computing, Faculty of Engineering, Universiti Teknologi Malaysia (UTM), Skudai Johor 81310, Malaysia"},{"name":"College of Computer Science, King Khalid University, Abha 61421, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Maheyzah","family":"Md Siraj","sequence":"additional","affiliation":[{"name":"School of Computing, Faculty of Engineering, Universiti Teknologi Malaysia (UTM), Skudai Johor 81310, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9939-1790","authenticated-orcid":false,"given":"Azath","family":"Mubarakali","sequence":"additional","affiliation":[{"name":"College of Computer Science, King Khalid University, Abha 61421, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9345-9264","authenticated-orcid":false,"given":"Omer","family":"Elsier Tayfour","sequence":"additional","affiliation":[{"name":"College of Computer Science, King Khalid University, Abha 61421, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7803-4994","authenticated-orcid":false,"given":"Sayeed","family":"Salih","sequence":"additional","affiliation":[{"name":"College of Computer and Information Sciences, King Saud University, Riyadh 11461, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1008-3028","authenticated-orcid":false,"given":"Mosab","family":"Hamdan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, University of S\u00e3o Paulo, S\u00e3o Paulo 13566-590, Brazil"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Suleman","family":"Khan","sequence":"additional","affiliation":[{"name":"School of Psychology and Computer Science, University of Central Lancashire, Preston PR1 2HE, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0022-3039","authenticated-orcid":false,"given":"Anazida","family":"Zainal","sequence":"additional","affiliation":[{"name":"School of Computing, Faculty of Engineering, Universiti Teknologi Malaysia (UTM), Skudai Johor 81310, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sameer","family":"Kamarudeen","sequence":"additional","affiliation":[{"name":"College of Computer Science, King Khalid University, Abha 61421, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Bhatti, D.G., and Virparia, P.V. (2020). Soft Computing-Based Intrusion Detection System with Reduced False Positive Rate. Design and Analysis of Security Protocol for Communication, Wiley Online Library.","DOI":"10.1002\/9781119555759.ch5"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s40537-020-00320-x","article-title":"A comprehensive survey of anomaly detection techniques for high dimensional big data","volume":"7","author":"Thudumu","year":"2020","journal-title":"J. Big Data"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1016\/j.procs.2020.04.070","article-title":"Shallow and Deep Learning Approaches for Network Intrusion Alert Prediction","volume":"171","author":"Ansari","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_4","first-page":"292","article-title":"Intrusion detection using data mining","volume":"9","author":"Puthran","year":"2020","journal-title":"Int. J. Comput. Intell. Stud."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Ayub, M.A., Johnson, W.A., Talbert, D.A., and Siraj, A. (2020, January 18\u201320). Model evasion attack on intrusion detection systems using adversarial machine learning. Proceedings of the 2020 54th Annual Conference on Information Sciences and Systems (CISS), Princeton, NJ, USA.","DOI":"10.1109\/CISS48834.2020.1570617116"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Kalnoor, G., and Gowri Shankar, S. (2022). A Model-Based System for Intrusion Detection Using Novel Technique-Hidden Markov Bayesian in Wireless Sensor Network. Information and Communication Technology for Competitive Strategies (ICTCS 2020), Springer.","DOI":"10.1007\/978-981-16-0739-4_4"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Negi, P.S., Garg, A., and Lal, R. (2020, January 29\u201331). Intrusion detection and prevention using honeypot network for cloud security. Proceedings of the 2020 10th International Conference on Cloud Computing, Data Science & Engineering (Confluence), Noida, India.","DOI":"10.1109\/Confluence47617.2020.9057961"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Jain, V., and Agrawal, M. (2020, January 15\u201317). Applying genetic algorithm in intrusion detection system of iot applications. Proceedings of the 2020 4th International Conference on Trends in Electronics and Informatics (ICOEI)(48184), Tirunelveli, India.","DOI":"10.1109\/ICOEI48184.2020.9143019"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"106301","DOI":"10.1016\/j.asoc.2020.106301","article-title":"A survey and taxonomy of the fuzzy signature-based intrusion detection systems","volume":"92","author":"Masdari","year":"2020","journal-title":"Appl. Soft Comput."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"102767","DOI":"10.1016\/j.jnca.2020.102767","article-title":"Deep learning methods in network intrusion detection: A survey and an objective comparison","volume":"169","author":"Gamage","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3472753","article-title":"A Survey on Data-driven Network Intrusion Detection","volume":"54","author":"Chou","year":"2021","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_12","unstructured":"Ahmed, N. (2021). Intrusion Detection System: A Survey and Taxonomy, HAL Open Science."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"233","DOI":"10.1080\/02564602.2014.906864","article-title":"A survey of intrusion alert correlation and its design considerations","volume":"31","author":"Ramadass","year":"2014","journal-title":"IETE Tech. Rev."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1289","DOI":"10.1016\/j.comnet.2012.10.022","article-title":"A model-based survey of alert correlation techniques","volume":"57","author":"Salah","year":"2013","journal-title":"Comput. Netw."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Sadoddin, R., and Ghorbani, A. (November, January 30). Alert correlation survey: Framework and techniques. Proceedings of the 2006 International Conference on Privacy, Security and Trust: Bridge the Gap between PST Technologies and Business Services, Markham, ON, Canada.","DOI":"10.1145\/1501434.1501479"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Mirheidari, S.A., Arshad, S., and Jalili, R. (2013, January 13\u201315). Alert correlation algorithms: A survey and taxonomy. Proceedings of the International Symposium on Cyberspace Safety and Security, Zhangjiajie, China.","DOI":"10.1007\/978-3-319-03584-0_14"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"101974","DOI":"10.1016\/j.cose.2020.101974","article-title":"Attack plan recognition using hidden Markov and probabilistic inference","volume":"97","author":"Li","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_18","unstructured":"Geib, C.W., and Goldman, R.P. (2001, January 12\u201314). Plan recognition in intrusion detection systems. Proceedings of the Proceedings DARPA Information Survivability Conference and Exposition II. DISCEX\u201901, Anaheim, CA, USA."},{"key":"ref_19","first-page":"102522","article-title":"Attack scenario reconstruction approach using attack graph and alert data mining","volume":"54","author":"Hu","year":"2020","journal-title":"J. Inf. Secur. Appl."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Zhang, K., Luo, S., Xin, Y., Zhu, H., and Chen, Y. (2020). Online Mining Intrusion Patterns from IDS Alerts. Appl. Sci., 10.","DOI":"10.3390\/app10082983"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Zhang, A.-F., Li, Z.-T., Li, D., and Wang, L. (2007, January 29\u201331). Discovering novel multistage attack patterns in alert streams. Proceedings of the 2007 International Conference on Networking, Architecture, and Storage (NAS 2007), Guilin, China.","DOI":"10.1109\/NAS.2007.20"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"101661","DOI":"10.1016\/j.cose.2019.101661","article-title":"A real-time alert correlation method based on code-books for intrusion detection systems","volume":"89","author":"Mahdavi","year":"2020","journal-title":"Comput. Secur."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"1564","DOI":"10.1109\/LCOMM.2020.3048995","article-title":"Discovering Attack Scenarios via Intrusion Alert Correlation Using Graph Convolutional Networks","volume":"25","author":"Cheng","year":"2021","journal-title":"IEEE Commun. Lett."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Cipriano, C., Zand, A., Houmansadr, A., Kruegel, C., and Vigna, G. (2011, January 5\u20139). Nexat: A history-based approach to predict attacker actions. Proceedings of the 27th Annual Computer Security Applications Conference, Orlando, FL, USA.","DOI":"10.1145\/2076732.2076787"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"210","DOI":"10.1007\/s10588-015-9182-0","article-title":"Learning and prediction of relational time series","volume":"21","author":"Tan","year":"2015","journal-title":"Comput. Math. Organ. Theory"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"833","DOI":"10.1002\/sec.786","article-title":"A Bayesian network-based approach for learning attack strategies from intrusion alerts","volume":"7","author":"Kavousi","year":"2014","journal-title":"Secur. Commun. Netw."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Liu, J., Liu, B., Zhang, R., and Wang, C. (2019, January 26\u201328). Multi-step Attack Scenarios Mining Based on Neural Network and Bayesian Network Attack Graph. Proceedings of the International Conference on Artificial Intelligence and Security, New York, NY, USA.","DOI":"10.1007\/978-3-030-24265-7_6"},{"key":"ref_28","first-page":"1","article-title":"The applications of deep learning on traffic identification","volume":"24","author":"Wang","year":"2015","journal-title":"BlackHat USA"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Chandra, B., and Sharma, R.K. (2015, January 12\u201316). Exploring autoencoders for unsupervised feature selection. Proceedings of the 2015 International Joint Conference on Neural Networks (IJCNN), Killarney, Ireland.","DOI":"10.1109\/IJCNN.2015.7280391"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"235","DOI":"10.1016\/j.future.2021.09.040","article-title":"GRU-based deep learning approach for network intrusion alert prediction","volume":"128","author":"Ansari","year":"2022","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"674","DOI":"10.1016\/j.future.2019.03.016","article-title":"Network entity characterization and attack prediction","volume":"97","author":"Bartos","year":"2019","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Chintabathina, S., Villacis, J., Walker, J.J., and Gomez, H.R. (2012, January 13\u201315). Plan recognition in intrusion detection systems using logic programming. Proceedings of the 2012 IEEE Conference on Technologies for Homeland Security (HST), Waltham, MA, USA.","DOI":"10.1109\/THS.2012.6459918"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"011004","DOI":"10.1115\/1.4044208","article-title":"Alert correlation for detecting cyber-manufacturing attacks and intrusions","volume":"20","author":"Wu","year":"2020","journal-title":"J. Comput. Inf. Sci. Eng."},{"key":"ref_34","unstructured":"Shin, Y., Lim, C., Park, M., Cho, S., Han, I., Oh, H., and Lee, K. (2019, January 4\u20135). Alert correlation using diamond model for cyber threat intelligence. Proceedings of the European Conference on Cyber Warfare and Security, Coimbra, Portugal."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Wang, W., Jiang, R., Jia, Y., Li, A., and Chen, Y. (2017, January 23\u201325). KGBIAC: Knowledge graph based intelligent alert correlation framework. Proceedings of the International Symposium on Cyberspace Safety and Security, Xi\u2019an, China.","DOI":"10.1007\/978-3-319-69471-9_41"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1","DOI":"10.17485\/ijst\/2015\/v8i12\/70658","article-title":"Towards predictive real-time multi-sensors intrusion alert correlation framework","volume":"8","author":"Siraj","year":"2015","journal-title":"Indian J. Sci. Technol."},{"key":"ref_37","first-page":"1","article-title":"Intelligent alert clustering model for network intrusion analysis","volume":"1","author":"Siraj","year":"2009","journal-title":"Int. J. Adv. Soft Comput. Appl."},{"key":"ref_38","unstructured":"Cuppens, F. (2001, January 10\u201314). Managing alerts in a multi-intrusion detection environment. Proceedings of the Seventeenth Annual Computer Security Applications Conference, New Orleans, LA, USA."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Valdes, A., and Skinner, K. (2001, January 10\u201312). Probabilistic alert correlation. Proceedings of the International Workshop on Recent Advances in Intrusion Detection, Davis, CA, USA.","DOI":"10.1007\/3-540-45474-8_4"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Elshoush, H.T., and Osman, I.M. (2013). Intrusion alert correlation framework: An innovative approach. IAENG Transactions on Engineering Technologies, Springer.","DOI":"10.1007\/978-94-007-6190-2_31"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"443","DOI":"10.1145\/950191.950192","article-title":"Clustering intrusion detection alarms to support root cause analysis","volume":"6","author":"Julisch","year":"2003","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"271","DOI":"10.1007\/s11416-008-0103-3","article-title":"Ids alerts correlation using grammar-based approach","volume":"5","author":"Zhang","year":"2009","journal-title":"J. Comput. Virol."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Dain, O., and Cunningham, R.K. (2002). Fusing a heterogeneous alert stream into scenarios. Applications of Data Mining in Computer Security, Springer.","DOI":"10.1007\/978-1-4615-0953-0_5"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Smith, R., Japkowicz, N., Dondo, M., and Mason, P. (2008, January 28\u201330). Using unsupervised learning for network alert correlation. Proceedings of the Conference of the Canadian Society for Computational Studies of Intelligence, Windsor, ON, Canada.","DOI":"10.1007\/978-3-540-68825-9_29"},{"key":"ref_45","unstructured":"Cheung, S., Lindqvist, U., and Fong, M.W. (2003, January 22\u201324). Modeling multistep cyber attacks for scenario recognition. Proceedings of the Proceedings DARPA Information Survivability Conference and Exposition, Washington, DC, USA."},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Kova\u010devi\u0107, I., Gro\u0161, S., and Slovenec, K. (2020). Systematic Review and Quantitative Comparison of Cyberattack Scenario Detection and Projection. Electronics, 9.","DOI":"10.3390\/electronics9101722"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Zali, Z., Hashemi, M.R., and Saidi, H. (2012, January 13\u201314). Real-time attack scenario detection via intrusion detection alert correlation. Proceedings of the 2012 9th International ISC Conference on Information Security and Cryptology, Tabriz, Iran.","DOI":"10.1109\/ISCISC.2012.6408197"},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Templeton, S.J., and Levitt, K. (2000, January 18\u201321). A requires\/provides model for computer attacks. Proceedings of the 2000 Workshop on New Security Paradigms, Ballycotton, Ireland.","DOI":"10.1145\/366173.366187"},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"274","DOI":"10.1145\/996943.996947","article-title":"Techniques and tools for analyzing intrusion alerts","volume":"7","author":"Ning","year":"2004","journal-title":"ACM Trans. Inf. Syst. Secur. (TISSEC)"},{"key":"ref_50","first-page":"244","article-title":"Alert correlation for extracting attack strategies","volume":"3","author":"Zhu","year":"2006","journal-title":"Int. J. Netw. Secur."},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"312","DOI":"10.1016\/j.inffus.2009.01.003","article-title":"Processing intrusion detection alert aggregates with time series modeling","volume":"10","author":"Viinikka","year":"2009","journal-title":"Inf. Fusion"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Melo, R.V., de Macedo, D.D., Kreutz, D., De Benedictis, A., and Fiorenza, M.M. (2021). ISM-AC: An immune security model based on alert correlation and software-defined networking. Int. J. Inf. Secur., 1\u201315.","DOI":"10.1007\/s10207-021-00550-x"},{"key":"ref_53","unstructured":"Ning, P., Xu, D., Healey, C.G., and Amant, R.S. (2004, January 5). Building Attack Scenarios through Integration of Complementary Alert Correlation Method. Proceedings of the NDSS, San Diego, CA, USA."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Yang, J., Zhang, Q., Jiang, X., Chen, S., and Yang, F. (2021). Poirot: Causal Correlation Aided Semantic Analysis for Advanced Persistent Threat Detection. IEEE Trans. Dependable Secur. Comput.","DOI":"10.1109\/TDSC.2021.3101649"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Alsubhi, K., Al-Shaer, E., and Boutaba, R. (2008, January 7\u201311). Alert prioritization in intrusion detection systems. Proceedings of the NOMS 2008\u20142008 IEEE Network Operations and Management Symposium, Salvador, Brazil.","DOI":"10.1109\/NOMS.2008.4575114"},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Asharf, J., Moustafa, N., Khurshid, H., Debie, E., Haider, W., and Wahab, A. (2020). A review of intrusion detection systems using machine and deep learning in internet of things: Challenges, solutions and future directions. Electronics, 9.","DOI":"10.3390\/electronics9071177"},{"key":"ref_57","unstructured":"Siraj, M.M., Maarof, M.A., and Hashim, S.Z.M. (2012, January 3\u20135). Classifying security alerts from multiple sensors based on hybrid approach. Proceedings of the International Conference on Informatics & Applications, Kuala Terengganu, Malaysia."},{"key":"ref_58","doi-asserted-by":"crossref","first-page":"636","DOI":"10.1016\/j.future.2020.03.014","article-title":"Analysis of hidden Markov model learning algorithms for the detection and prediction of multi-stage network attacks","volume":"108","author":"Chadza","year":"2020","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Debar, H., and Wespi, A. (2001, January 10\u201312). Aggregation and correlation of intrusion-detection alerts. Proceedings of the International Workshop on Recent Advances in Intrusion Detection, Davis, CA, USA.","DOI":"10.1007\/3-540-45474-8_6"},{"key":"ref_60","unstructured":"K\u00e1cha, P. (2014, January 17\u201321). Idea: Security event taxonomy mapping. Proceedings of the 18th International Conference on Circuits, Systems, Communications and Computers, Santorini Island, Greece."},{"key":"ref_61","doi-asserted-by":"crossref","unstructured":"Roschke, S., Cheng, F., and Meinel, C. (2011). A new alert correlation algorithm based on attack graph. Computational Intelligence in Security for Information Systems, Springer.","DOI":"10.1007\/978-3-642-21323-6_8"},{"key":"ref_62","doi-asserted-by":"crossref","first-page":"3033","DOI":"10.1016\/j.proeng.2012.01.435","article-title":"An alert aggregation algorithm based on iterative self-organization","volume":"29","author":"Man","year":"2012","journal-title":"Procedia Eng."},{"key":"ref_63","doi-asserted-by":"crossref","first-page":"176","DOI":"10.1016\/j.cose.2013.03.005","article-title":"Enhancing IDS performance through comprehensive alert post-processing","volume":"37","author":"Spathoulas","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_64","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1002\/nem.1857","article-title":"An efficient approach to reduce alerts generated by multiple IDS products","volume":"24","author":"Nguyen","year":"2014","journal-title":"Int. J. Netw. Manag."},{"key":"ref_65","doi-asserted-by":"crossref","unstructured":"Sadighian, A., Fernandez, J.M., Lemay, A., and Zargar, S.T. (2013, January 21\u201322). Ontids: A highly flexible context-aware and ontology-based alert correlation framework. Proceedings of the International Symposium on Foundations and Practice of Security, La Rochelle, France.","DOI":"10.1007\/978-3-319-05302-8_10"},{"key":"ref_66","doi-asserted-by":"crossref","unstructured":"Zomlot, L., Chandran, S., Caragea, D., and Ou, X. (2013, January 4\u20137). Aiding intrusion analysis using machine learning. Proceedings of the 2013 12th International Conference on Machine Learning and Applications, Miami, FL, USA.","DOI":"10.1109\/ICMLA.2013.103"},{"key":"ref_67","doi-asserted-by":"crossref","unstructured":"Long, J., Schwartz, D., and Stoecklin, S. (2006, January 18). Distinguishing false from true alerts in snort by data mining patterns of alerts. Proceedings of the Data Mining, Intrusion Detection, Information Assurance, and Data Networks Security, Orlando, FL, USA.","DOI":"10.1117\/12.665211"},{"key":"ref_68","unstructured":"Maggi, F., and Zanero, S. (2007, January 5\u20137). On the use of different statistical tests for alert correlation\u2013short paper. Proceedings of the International Workshop on Recent Advances in Intrusion Detection, Gold Goast, Australia."},{"key":"ref_69","first-page":"2865","article-title":"Application of type-2 fuzzy logic to rule-based intrusion alert correlation detection","volume":"8","author":"Huang","year":"2012","journal-title":"Int. J. Innov. Comput. Inf. Control"},{"key":"ref_70","first-page":"228","article-title":"Fuzzy classifier for ids alerts using genetic algorithm","volume":"2","author":"Hassan","year":"2014","journal-title":"Int. J. Res."},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Ghorbani, A.A., Lu, W., and Tavallaee, M. (2010). Alert management and correlation. Network Intrusion Detection and Prevention, Springer.","DOI":"10.1007\/978-0-387-88771-5"},{"key":"ref_72","doi-asserted-by":"crossref","first-page":"539","DOI":"10.7763\/IJCTE.2009.V1.87","article-title":"A hybrid intelligent approach for automated alert clustering and filtering in intrusion alert analysis","volume":"1","author":"Siraj","year":"2009","journal-title":"Int. J. Comput. Theory Eng."},{"key":"ref_73","doi-asserted-by":"crossref","unstructured":"Nehinbe, J.O. (2011, January 1\u20132). A critical evaluation of datasets for investigating IDSs and IPSs researches. Proceedings of the 2011 IEEE 10th International Conference on Cybernetic Intelligent Systems (CIS), London, UK.","DOI":"10.1109\/CIS.2011.6169141"},{"key":"ref_74","doi-asserted-by":"crossref","first-page":"636","DOI":"10.1016\/j.procs.2020.03.330","article-title":"A review of the advancement in intrusion detection datasets","volume":"167","author":"Thakkar","year":"2020","journal-title":"Procedia Comput. Sci."},{"key":"ref_75","unstructured":"UCI KDD University of California (2021, October 15). KDD Cup 99 Dataset. 1999. Available online: http:\/\/kdd.ics.uci.edu\/databases\/kddcup99\/kddcup99.html."},{"key":"ref_76","unstructured":"MIT (2021, October 15). MIT Lincoln Laboratory, D.I.D.E. DARPA Intrusion Detection. 2000. Available online: https:\/\/archive.ll.mit.edu\/ideval\/data\/2000data.html."},{"key":"ref_77","doi-asserted-by":"crossref","first-page":"579","DOI":"10.1016\/S1389-1286(00)00139-0","article-title":"The 1999 DARPA off-line intrusion detection evaluation","volume":"34","author":"Lippmann","year":"2000","journal-title":"Comput. Netw."},{"key":"ref_78","unstructured":"Kyoto University\u2019s (2021, October 15). Traffic Data from Kyoto University\u2019s Honeypots. 2006. Available online: https:\/\/www.takakura.com\/Kyoto_data\/."},{"key":"ref_79","doi-asserted-by":"crossref","unstructured":"Song, J., Takakura, H., Okabe, Y., Eto, M., Inoue, D., and Nakao, K. (2011, January 10). Statistical analysis of honeypot data and building of Kyoto 2006+ dataset for NIDS evaluation. Proceedings of the First Workshop on Building Analysis Datasets and Gathering Experience Returns for Security, Salzburg, Austria.","DOI":"10.1145\/1978672.1978676"},{"key":"ref_80","doi-asserted-by":"crossref","first-page":"106530","DOI":"10.1016\/j.dib.2020.106530","article-title":"Dataset of intrusion detection alerts from a sharing platform","volume":"33","author":"Sokol","year":"2020","journal-title":"Data Brief"},{"key":"ref_81","doi-asserted-by":"crossref","unstructured":"Pekar\u010d\u00edk, P., Gajdo\u0161, A., and Sokol, P. (2020, January 11\u201313). Forecasting Security Alerts Based on Time Series. Proceedings of the International Conference on Hybrid Artificial Intelligence Systems, Gij\u00f3n, Spain.","DOI":"10.1007\/978-3-030-61705-9_45"},{"key":"ref_82","doi-asserted-by":"crossref","unstructured":"Hus\u00e1k, M., and \u010celeda, P. (2020, January 20\u201324). Predictions of Network Attacks in Collaborative Environment. Proceedings of the NOMS 2020\u20142020 IEEE\/IFIP Network Operations and Management Symposium, Budapest, Hungary.","DOI":"10.1109\/NOMS47738.2020.9110472"},{"key":"ref_83","doi-asserted-by":"crossref","unstructured":"Sallay, H., Ammar, A., Saad, M.B., and Bourouis, S. (2013, January 22\u201324). A real time adaptive intrusion detection alert classifier for high speed networks. Proceedings of the 2013 IEEE 12th International Symposium on Network Computing and Applications, Cambridge, MA, USA.","DOI":"10.1109\/NCA.2013.16"},{"key":"ref_84","unstructured":"Lyons, K.B. (2014). A Recommender System in the Cyber Defense Domain, AFIT Scholar."},{"key":"ref_85","doi-asserted-by":"crossref","first-page":"222","DOI":"10.1016\/j.patcog.2009.05.017","article-title":"A triangle area based nearest neighbors approach to intrusion detection","volume":"43","author":"Tsai","year":"2010","journal-title":"Pattern Recognit."},{"key":"ref_86","doi-asserted-by":"crossref","first-page":"360","DOI":"10.1016\/j.asoc.2015.10.011","article-title":"A novel SVM-kNN-PSO ensemble method for intrusion detection system","volume":"38","author":"Aburomman","year":"2016","journal-title":"Appl. Soft Comput."},{"key":"ref_87","doi-asserted-by":"crossref","first-page":"306","DOI":"10.1016\/j.eswa.2010.06.066","article-title":"A novel intrusion detection system based on hierarchical clustering and support vector machines","volume":"38","author":"Horng","year":"2011","journal-title":"Expert Syst. Appl."},{"key":"ref_88","doi-asserted-by":"crossref","first-page":"507","DOI":"10.1007\/s00778-006-0002-5","article-title":"A new intrusion detection system using support vector machines and hierarchical clustering","volume":"16","author":"Khan","year":"2007","journal-title":"VLDB J."},{"key":"ref_89","doi-asserted-by":"crossref","first-page":"226","DOI":"10.1016\/j.procs.2017.09.129","article-title":"RFAODE: A novel ensemble intrusion detection system","volume":"115","author":"Jabbar","year":"2017","journal-title":"Procedia Comput. Sci."},{"key":"ref_90","doi-asserted-by":"crossref","first-page":"1881","DOI":"10.1016\/j.comcom.2009.07.013","article-title":"Network forensics based on fuzzy logic and expert system","volume":"32","author":"Liao","year":"2009","journal-title":"Comput. Commun."},{"key":"ref_91","doi-asserted-by":"crossref","unstructured":"Chadha, K., and Jain, S. (2015). Hybrid genetic fuzzy rule based inference engine to detect intrusion in networks. Intelligent Distributed Computing, Springer.","DOI":"10.1007\/978-3-319-11227-5_17"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/4\/1494\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:19:57Z","timestamp":1760134797000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/4\/1494"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,15]]},"references-count":91,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["s22041494"],"URL":"https:\/\/doi.org\/10.3390\/s22041494","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,15]]}}}