Co-stimulation Algorithms
- Simple conditional rules (if attribute X present at time of alert, then...)
- Bayesian decision processing (Kruegel, Mutz, Robertson, Valeur)
- unsupervised learning with profile tuning through human feedback (supervised inclusion or exclusion of data that was associated with a false positive)
There is great academic work in this area, but we need more implementations to actually determine the value in operational environments.