Prioritize Threat Alerts Based on False Positives Qualifiers Provided by Multiple AI Models Using Evolutionary Computation and Reinforcement Learning
摘要
The field of intrusion detection systems continues to grapple with the persistent challenge of false positives, despite various approaches like clustering and fuzzy logic. This research introduces a predictive AI model to prioritize threat alerts based on false positive qualifiers, aiming to contribute to the development of intrusion-free computer networks. The model reduces alert fatigue and enhances the accuracy of threat identification and response, bolstering network security and alleviating the workload on security personnel. The research emphasizes the potential of the predictive AI model to revolutionize intrusion detection and the critical importance of ongoing research in this area to safeguard computer networks against evolving threats. The work represents a significant step towards creating more secure and intrusion-resistant networks, thus advancing the field of cybersecurity. The research's performance evaluations are conducted using the WEKA tool, and the results are analysed alongside existing research in the domain. The proposed method compares machine learning results against existing rule-based security systems using both conventional and unique predictive risk indices. However, unlike peer observation or rule-based detection, it is independent. The method's effectiveness is attributed to its high false positives (84,100%) and low genuine negatives (023%), possibly due to a mix of real network traffic and CERT threat stories and a poor signal-to-noise ratio.