Abstract : In order to relieve the alarm fatigue of security analysts and improve the security operation efficiency, an attacker IP analysis system based on the Ensemble-based Local Outlier Factor algorithm (EBLOF) was proposed in this paper. Firstly, normalized network security alarm logs were extracted and merged, and then the feature engineering was constructed from the attribute dimension and attack behavior dimension of attacker IP. Secondly, inspired by the idea of ensemble learning and traditional L
Keywords : EBLOF, Analysis System Based, Application In, Local Outlier Factor, attacker