where
Kn = Lmj (ej)m2(e2)···mn(en)
When the security situation sensor receives the security
alert event, the first thing to do is to calculate the confidence
level of the event based upon the system settings or the
arguments of the rules. It can effectively reduce the false
alert rate that quantifies the confidence degree of the alerts
from the level of primitive events. During the phase of alert
data processing, the alert events collected from sensors have
the quantified confidence level, the redundant and suspect
alert events can be greatly reduced and the ability of
identifying the attack behavior can be improved through the
fusion of security alert events based upon the Dempster rule.