├── LICENSE ├── README.md ├── aggregate.py ├── aggregate_config.py ├── attacktimes.py ├── clustering ├── objects.py └── time_delta_group.py ├── data ├── aminer │ ├── aminer_cup.txt │ ├── aminer_insect.txt │ ├── aminer_onion.txt │ └── aminer_spiral.txt ├── ossec │ ├── ossec_cup.json │ ├── ossec_insect.json │ ├── ossec_onion.json │ └── ossec_spiral.json ├── out │ ├── aggregate │ │ └── meta_alerts.txt │ ├── cross_validation │ │ ├── attack_similarities_matrix_0_2.txt │ │ ├── attack_similarities_matrix_0_3.txt │ │ ├── attack_similarities_matrix_0_4.txt │ │ ├── confusion_matrix_0_2.txt │ │ ├── confusion_matrix_0_3.txt │ │ ├── confusion_matrix_0_4.txt │ │ ├── cross_corr.txt │ │ ├── reductions.txt │ │ └── sim_list.txt │ ├── evaluation │ │ ├── evaluation.txt │ │ └── number_groups.txt │ ├── hierarchical │ │ └── hierarchical_clustering.R │ ├── mds │ │ ├── mds_sim_matrix.txt │ │ └── mds_sim_matrix_meta.txt │ ├── noise │ │ ├── attack_similarities_matrix_0_3.txt │ │ ├── confusion_matrix_0_3.txt │ │ ├── noise.txt │ │ ├── noise_number_groups.txt │ │ ├── reductions.txt │ │ └── sim_list.txt │ └── sample │ │ ├── alerts.txt │ │ └── meta_alerts.txt └── sample │ ├── test_cup.txt │ └── test_spiral.txt ├── evaluation ├── cross_validation.py ├── evaluate.py ├── hierarchical_clustering.py ├── mds.py └── noise_evaluate.py ├── merging ├── merge.py └── objects.py ├── preprocessing ├── label.py ├── objects.py ├── preprocess.py └── read_input.py ├── requirements.txt ├── samples ├── sample.py ├── sample_group_merge.py ├── sample_group_similarity.py ├── sample_hierarchical_clustering.py ├── sample_merge.py └── sample_similarity.py └── similarity └── similarity.py /LICENSE: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/LICENSE -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/README.md -------------------------------------------------------------------------------- /aggregate.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/aggregate.py -------------------------------------------------------------------------------- /aggregate_config.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/aggregate_config.py -------------------------------------------------------------------------------- /attacktimes.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/attacktimes.py -------------------------------------------------------------------------------- /clustering/objects.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/clustering/objects.py -------------------------------------------------------------------------------- /clustering/time_delta_group.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/clustering/time_delta_group.py -------------------------------------------------------------------------------- /data/aminer/aminer_cup.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/aminer/aminer_cup.txt -------------------------------------------------------------------------------- /data/aminer/aminer_insect.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/aminer/aminer_insect.txt -------------------------------------------------------------------------------- /data/aminer/aminer_onion.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/aminer/aminer_onion.txt -------------------------------------------------------------------------------- /data/aminer/aminer_spiral.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/aminer/aminer_spiral.txt -------------------------------------------------------------------------------- /data/ossec/ossec_cup.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/ossec/ossec_cup.json -------------------------------------------------------------------------------- /data/ossec/ossec_insect.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/ossec/ossec_insect.json -------------------------------------------------------------------------------- /data/ossec/ossec_onion.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/ossec/ossec_onion.json -------------------------------------------------------------------------------- /data/ossec/ossec_spiral.json: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/ossec/ossec_spiral.json -------------------------------------------------------------------------------- /data/out/aggregate/meta_alerts.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/aggregate/meta_alerts.txt -------------------------------------------------------------------------------- /data/out/cross_validation/attack_similarities_matrix_0_2.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/attack_similarities_matrix_0_2.txt -------------------------------------------------------------------------------- /data/out/cross_validation/attack_similarities_matrix_0_3.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/attack_similarities_matrix_0_3.txt -------------------------------------------------------------------------------- /data/out/cross_validation/attack_similarities_matrix_0_4.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/attack_similarities_matrix_0_4.txt -------------------------------------------------------------------------------- /data/out/cross_validation/confusion_matrix_0_2.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/confusion_matrix_0_2.txt -------------------------------------------------------------------------------- /data/out/cross_validation/confusion_matrix_0_3.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/confusion_matrix_0_3.txt -------------------------------------------------------------------------------- /data/out/cross_validation/confusion_matrix_0_4.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/confusion_matrix_0_4.txt -------------------------------------------------------------------------------- /data/out/cross_validation/cross_corr.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/cross_corr.txt -------------------------------------------------------------------------------- /data/out/cross_validation/reductions.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/reductions.txt -------------------------------------------------------------------------------- /data/out/cross_validation/sim_list.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/cross_validation/sim_list.txt -------------------------------------------------------------------------------- /data/out/evaluation/evaluation.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/evaluation/evaluation.txt -------------------------------------------------------------------------------- /data/out/evaluation/number_groups.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/evaluation/number_groups.txt -------------------------------------------------------------------------------- /data/out/hierarchical/hierarchical_clustering.R: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/hierarchical/hierarchical_clustering.R -------------------------------------------------------------------------------- /data/out/mds/mds_sim_matrix.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/mds/mds_sim_matrix.txt -------------------------------------------------------------------------------- /data/out/mds/mds_sim_matrix_meta.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/mds/mds_sim_matrix_meta.txt -------------------------------------------------------------------------------- /data/out/noise/attack_similarities_matrix_0_3.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/noise/attack_similarities_matrix_0_3.txt -------------------------------------------------------------------------------- /data/out/noise/confusion_matrix_0_3.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/noise/confusion_matrix_0_3.txt -------------------------------------------------------------------------------- /data/out/noise/noise.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/noise/noise.txt -------------------------------------------------------------------------------- /data/out/noise/noise_number_groups.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/noise/noise_number_groups.txt -------------------------------------------------------------------------------- /data/out/noise/reductions.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/noise/reductions.txt -------------------------------------------------------------------------------- /data/out/noise/sim_list.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/noise/sim_list.txt -------------------------------------------------------------------------------- /data/out/sample/alerts.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/sample/alerts.txt -------------------------------------------------------------------------------- /data/out/sample/meta_alerts.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/out/sample/meta_alerts.txt -------------------------------------------------------------------------------- /data/sample/test_cup.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/sample/test_cup.txt -------------------------------------------------------------------------------- /data/sample/test_spiral.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/data/sample/test_spiral.txt -------------------------------------------------------------------------------- /evaluation/cross_validation.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/evaluation/cross_validation.py -------------------------------------------------------------------------------- /evaluation/evaluate.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/evaluation/evaluate.py -------------------------------------------------------------------------------- /evaluation/hierarchical_clustering.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/evaluation/hierarchical_clustering.py -------------------------------------------------------------------------------- /evaluation/mds.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/evaluation/mds.py -------------------------------------------------------------------------------- /evaluation/noise_evaluate.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/evaluation/noise_evaluate.py -------------------------------------------------------------------------------- /merging/merge.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/merging/merge.py -------------------------------------------------------------------------------- /merging/objects.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/merging/objects.py -------------------------------------------------------------------------------- /preprocessing/label.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/preprocessing/label.py -------------------------------------------------------------------------------- /preprocessing/objects.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/preprocessing/objects.py -------------------------------------------------------------------------------- /preprocessing/preprocess.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/preprocessing/preprocess.py -------------------------------------------------------------------------------- /preprocessing/read_input.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/preprocessing/read_input.py -------------------------------------------------------------------------------- /requirements.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/requirements.txt -------------------------------------------------------------------------------- /samples/sample.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/samples/sample.py -------------------------------------------------------------------------------- /samples/sample_group_merge.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/samples/sample_group_merge.py -------------------------------------------------------------------------------- /samples/sample_group_similarity.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/samples/sample_group_similarity.py -------------------------------------------------------------------------------- /samples/sample_hierarchical_clustering.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/samples/sample_hierarchical_clustering.py -------------------------------------------------------------------------------- /samples/sample_merge.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/samples/sample_merge.py -------------------------------------------------------------------------------- /samples/sample_similarity.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/samples/sample_similarity.py -------------------------------------------------------------------------------- /similarity/similarity.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/ait-aecid/aecid-alert-aggregation/HEAD/similarity/similarity.py --------------------------------------------------------------------------------