alert always
8.In the applying of distributed intru-sion detection systems ,control centers always aggregate large numbers of alert data so that they cannot be dealt with and responded in time. In order to improve efficiency and veracity of intrusion analysis,the authors abstract intrusion in-tensity value and entity number value from alert data and use statistical approach to detect anomaly.


