To overcome the shortcoming of current alert correlation methods which didn’t consider the confidence of IDS
an alert correlation method based on alerts confidence using the evidence theory was presented.Each alert was regarded as a piece of evidence of a network attack.Then multiple pieces of evidence were combined by the Dempster’s combina-tion rule
and used to infer whether the attack corresponding to the alerts took place.As a result
the ambiguity and con-fliction in alerts were eliminated
achieving the goal of improving alerts quality.Experimental results on the DARPA 2000 IDS test dataset show that the proposed method can efficiently decrease the false alert rate and reduce more than 60% of the alerts.