Related Experiment Video
Updated: Oct 2, 2025

Author Spotlight: Addressing Technical and Subjective Challenges in Measuring Classroom Attention
Published on: December 15, 2023
Cyber-Attack Prediction Based on Network Intrusion Detection Systems for Alert Correlation Techniques: A Survey.
Hashim Albasheer1,2, Maheyzah Md Siraj1, Azath Mubarakali2
1School of Computing, Faculty of Engineering, Universiti Teknologi Malaysia (UTM), Skudai Johor 81310, Malaysia.
Network Intrusion Detection Systems generate many false positives. This review explores alert correlation methods to improve cyber-attack prediction and network security effectiveness.
Area of Science:
- Cybersecurity
- Network Security
- Intrusion Detection Systems
Background:
- Network Intrusion Detection Systems (NIDS) are crucial for enterprise network security but generate numerous low-quality alerts, with up to 99% being false positives.
- Predicting attacker actions is a key goal for enhancing NIDS effectiveness.
- Existing NIDS face limitations in accurately identifying and prioritizing threats.
Purpose of the Study:
- To review the state-of-the-art in cyber-attack prediction using Network Intrusion Detection System (NIDS) alerts.
- To introduce a taxonomy of intrusion alert correlation (AC) approaches and components.
- To highlight datasets and future research directions in alert correlation.
Main Methods:
- Review of current literature on NIDS and cyber-attack prediction.
- Introduction of a taxonomy for alert correlation (AC) methods: similarity-based, statistical-based, knowledge-based, and hybrid-based.
- Classification of alert correlation components.
Main Results:
- Alert correlation (AC) processes raw alerts to identify associations between them.
- AC links alerts to contextual information and predicts future attacks.
- AC offers a concise, high-level overview of network security status.
Conclusions:
- Alert correlation is essential for improving the accuracy and predictive capabilities of NIDS.
- This review provides a benchmark for future research and development in NIDS and alert correlation.
- Effective AC can significantly enhance enterprise network defense strategies.
More Related Videos
Related Concept Videos
Steps in Outbreak Investigation
Distribution Reliability and Automation
Correlation and Regression
Nursing Clinical Information System
A Nursing Clinical Information System (NCIS) is a specialized type of healthcare information system tailored to meet the unique needs of nursing practice. It incorporates the principles of nursing informatics to streamline information management and improve the quality of care delivery.
Critical attributes of NCIS include:
Cause and Effect
Pharmacovigilance
This process, termed pharmacovigilance, aims to detect, evaluate, and minimize harmful effects related to medication use. The data collection for pharmacovigilance depends on spontaneous reporting systems, where healthcare professionals or patients voluntarily report suspected ADRs.
In some cases, there...

