Network Intrusion Detection System Model Based on Data Mining

被引:0
作者
Zhao, Yanjie [1 ]
机构
[1] Weifang Univ, Sch Comp Engn, Weifang, Peoples R China
来源
2016 17TH IEEE/ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCE, NETWORKING AND PARALLEL/DISTRIBUTED COMPUTING (SNPD) | 2016年
关键词
intrusion detection system; data mining; network security;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The paper's object is to develop a network intrusion detection model based on data mining technology, which can detect known intrusion effectively and has a good capacity to recognize unknown data schema which can't be detected effectively in traditional IDS. The paper mainly does the following work: by analyzing the intrusion deeply, extract the properties which can reflect intrusion characteristics effectively; combine misuse detection, anomaly detection and human intervention, establish rule library based on C.45 decision tree algorithm and use the optimal pattern matching so as to improve detection rate; the hosts are clustered to be IP group based on visit number by k-means clustering algorithm, the audit data are divided into parts under the IP group's direction, and the classifiers are built up by divided audit data respectively, then the detected Data apply different rules according to their own IP group, thereby reduce false positives. The experiments proved that the method is effective to detect intrusion such as scanning and Deny of Service.
引用
收藏
页码:155 / 160
页数:6
相关论文
共 10 条
[1]  
Al-Jarrah O., 2014 15 INT C INF CO, P1
[2]  
Beniwal S., 2012, International Journal of Engineering Research Technology (IJERT), V1, P1
[3]  
Lee W., 2000, ACM Transactions on Information and Systems Security, V3, P227, DOI 10.1145/382912.382914
[4]  
Lee W., 1998, P 7 C USENIX SEC S, V7, P7
[5]  
Lee Wenke, 1999, SEC PRIV 1999 P 1999
[6]  
LUNT TF, 1988, SRICSL8812
[7]  
Othman Z. A., 2010, INT SYST DES APPL IS
[8]  
PORRAS P, 1998, COMMON INTRUSION DET
[9]  
Relan NG, 2015, 2015 INTERNATIONAL CONFERENCE ON NASCENT TECHNOLOGIES IN THE ENGINEERING FIELD (ICNTE)
[10]  
Wanlei Z., 2012, P IEEE 11 INT C ONTR