Concepedia

Publication | Open Access

NoDoze: Combatting Threat Alert Fatigue with Automated Provenance Triage

285

Citations

39

References

2019

Year

Abstract

Large enterprises are increasingly relying on threat detection softwares (e.g., Intrusion Detection Systems) to allow them to spot suspicious activities. These softwares generate alerts which must be investigated by cyber analysts to figure out if they are true attacks. Unfortunately, in practice, there are more alerts than cyber analysts can properly investigate. This leads to a "threat alert fatigue" or information overload problem where cyber analysts miss true attack alerts in the noise of false alarms.

References

YearCitations

Page 1