Skip to main navigation Skip to search Skip to main content

On the Effect of Ruleset Tuning and Data Imbalance on Explainable Network Security Alert Classifications: a Case-Study on DeepCASE

Research output: Chapter in Book/Report/Conference proceedingConference contributionAcademicpeer-review

42 Downloads (Pure)

Abstract

Automation in Security Operations Centers (SOCs) plays a prominent role in alert classification and incident escalation. However, automated methods must be robust in the presence of imbalanced input data, which can negatively affect performance. Additionally, automated methods should make explainable decisions. In this work, we evaluate the effect of label imbalance on the classification of network intrusion alerts. As our use-case we employ DeepCASE, the state-of-the-art method for automated alert classification. We show that label imbalance impacts both classification performance and correctness of the classification explanations offered by DeepCASE. We conclude tuning the detection rules used in SOCs can significantly reduce imbalance and may benefit the performance and explainability offered by alert post-processing methods such as DeepCASE. Therefore, our findings suggest that traditional methods to improve the quality of input data can benefit automation.
Original languageEnglish
Title of host publication10th IEEE European Symposium on Security and Privacy Workshops, EuroS&PW 2025
PublisherInstitute of Electrical and Electronics Engineers
Pages16-29
Number of pages14
ISBN (Electronic)979-8-3315-9546-3
DOIs
Publication statusPublished - 1 Sept 2025
Event10th IEEE European Symposium on Security and Privacy Workshops, EUROS&PW 2025 - Venice, Italy
Duration: 30 Jun 20254 Jul 2025

Conference

Conference10th IEEE European Symposium on Security and Privacy Workshops, EUROS&PW 2025
Abbreviated titleEUROS&PW 2025
Country/TerritoryItaly
CityVenice
Period30/06/254/07/25

Funding

Parts of this work were derived from a prior M.Sc. graduation project [41]. The authors thank the unnamed SOC for their cooperation and for making data available for analysis, and Thijs van Ede discussing DeepCASE with us. This publication is part of the CATRIN, INTERSECT, and SeReNity projects (with numbers NWA.1215.18.003, NWA.1160.18.301, and CS.010) which are (partly) financed by the Dutch Research Council (NWO). For the purpose of Open Access, a CC-BY 4.0 public copyright license is applied to any Author Accepted Manuscript version arising from this submission.

FundersFunder number
Nederlandse Organisatie voor Wetenschappelijk OnderzoekNWA.1215.18.003
Nederlandse Organisatie voor Wetenschappelijk OnderzoekNWA.1160.18.301
Nederlandse Organisatie voor Wetenschappelijk OnderzoekCS.010

    UN SDGs

    This output contributes to the following UN Sustainable Development Goals (SDGs)

    1. SDG 16 - Peace, Justice and Strong Institutions
      SDG 16 Peace, Justice and Strong Institutions

    Keywords

    • Security Operations Center (SOC)
    • Network Intrusion Detection System (NIDS)
    • Network Security Alerts
    • Alert Reduction
    • Intrusion Detection Ruleset Tuning
    • Network Intrusion Detection Rules

    Fingerprint

    Dive into the research topics of 'On the Effect of Ruleset Tuning and Data Imbalance on Explainable Network Security Alert Classifications: a Case-Study on DeepCASE'. Together they form a unique fingerprint.

    Cite this