One of the most important steps in attack detection using Intrusion Detection Systems (IDSs) is dealing with huge number of alerts that can be either critical single alerts and multi-step attack scenarios or false alerts and non-critical ones. In this paper we try to address the problem of managing alerts via a multi-layer alert correlation and ltering that can identify critical alerts after each step of correlation and ltering. After applying
Mahboobeh Soleimani, Ali A. Ghorbani