Using decision trees to improve signature-based intrusion detection

被引:0
|
作者
Kruegel, C [1 ]
Toth, T
机构
[1] Univ Calif Santa Barbara, Reliable Software Grp, Santa Barbara, CA 93106 USA
[2] Tech Univ Vienna, Distributed Syst Grp, Vienna, Austria
关键词
signature-based intrusion detection; machine learning; network security;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Most deployed intrusion detection systems (IDSs) follow a signature-based approach where attacks are identified by matching each input event against predefined signatures that model malicious activity. This matching process accounts for the most resource intensive task of an IDS. Many systems perform the matching by comparing each input event to all rules sequentially. This is far from being optimal. Although sometimes ad-hoc optimizations axe utilized, no general solution to this problem has been proposed so far. This paper describes an approach where machine learning clustering techniques are applied to improve the matching process. Given a set of signatures (each dictating. a number of constraints the input data must fulfill to trigger it) an algorithm generates a decision tree that is used to find malicious events using as few redundant comparisons as possible. This general idea has been applied to a network-based IDS. In particular, a system has been implemented that replaces the detection engine of Snort [14,16]. Experimental evaluation shows that the speed of the detection process has been significantly improved, even compared to Snort's recently released, fully revised detection engine.
引用
收藏
页码:173 / 191
页数:19
相关论文
共 50 条
  • [1] Pre-decision detection engine for signature-based network intrusion detection system
    College of Computer Science and Technology, Zhejiang University, Hangzhou 310027, China
    Zhejiang Daxue Xuebao (Gongxue Ban), 2006, 10 (1701-1704):
  • [2] Characterizing Realistic Signature-based Intrusion Detection Benchmarks
    Aldwairi, Monther
    Alshboul, Mohammad A.
    Seyam, Asmaa
    PROCEEDINGS OF THE 6TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: IOT AND SMART CITY (ICIT 2018), 2018, : 97 - 103
  • [3] Signature-Based Anomaly Intrusion Detection using Integrated Data Mining Classifiers
    Yassin, Warusia
    Udzir, Nur Izura
    Abdullah, Azizol
    Abdullah, Mohd Taufik
    Zulzalil, Hazura
    Muda, Zaiton
    2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 232 - 237
  • [4] Improve intrusion detection using grasshopper optimization algorithm and decision trees
    Hosseiny S.M.
    Rahmani A.I.
    Derakhshan M.
    International Journal of Safety and Security Engineering, 2020, 10 (03) : 359 - 364
  • [5] CBSigIDS: Towards Collaborative Blockchained Signature-based Intrusion Detection
    Tug, Steven
    Meng, Weizhi
    Wang, Yu
    IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 1228 - 1235
  • [6] Attack Resilient Trust and Signature-based Intrusion Detection Systems
    Kabaso, Boniface
    Aradeh, Saber A.
    Abidoye, Ademola P.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (03) : 701 - 707
  • [7] A survey and taxonomy of the fuzzy signature-based Intrusion Detection Systems
    Masdari, Mohammad
    Khezri, Hemn
    APPLIED SOFT COMPUTING, 2020, 92 (92)
  • [8] USAID: Unifying signature-based and anomaly-based intrusion detection
    Li, ZW
    Das, A
    Zhou, JY
    ADVANCES IN KNOWLEDGE DISCOVERY AND DATA MINING, PROCEEDINGS, 2005, 3518 : 702 - 712
  • [9] Advanced Intrusion Detection Combining Signature-Based and Behavior-Based Detection Methods
    Kwon, Hee-Yong
    Kim, Taesic
    Lee, Mun-Kyu
    ELECTRONICS, 2022, 11 (06)
  • [10] On the Detection Capabilities of Signature-Based Intrusion Detection Systems in the Context of Web Attacks
    Diaz-Verdejo, Jesus
    Munoz-Calle, Javier
    Estepa Alonso, Antonio
    Estepa Alonso, Rafael
    Madinabeitia, German
    APPLIED SCIENCES-BASEL, 2022, 12 (02):