Free and Latest article publishing for websites and ezines!

Study on Data Mining Based Intrusion Detection Approaches and System

Intrusion detection system (IDS) plays important roles in the information security architecture. The computer criminal is more and more pressing and dangerous nowadays, which poses urgent demands on the performance of IDS. The big shortcoming of current IDS is unable to detect intrusion behavior quickly when facing large amount of audit data, unable to detect new type of attacks, and high false positive rate which influence greatly the performance of IDS. A new intrusion detection approach was put forward in this dissertation and a Network-based Anomaly Intrusion Detection System (NAIDS) was implemented based on those approaches.Based on the detailed and comprehensive study on data mining based intrusion detection techniques, NAIDS apply the association rule and classification techniques into detecting intrusion behavior among network audit record from a new perspective. Aspect to association rules mining, constructing two mining modes: static mining and dynamic mining; implementing two level mining: single-level mining and domain-level mining. About classification engineering, the mainstream classification techniques were compared through thoroughly experiments, and some improvement was made to decision tree toward the concrete problem, which make NAIDS detect some new type attacks and this kind of capability embodies the advantage of anomaly detection over misuse detection; incremental mining approach was put forward which detect one window data amount, instead of batch of tcp/ip record, which was very suitable to on-line mining and make NAIDS be high real-time performance.Research work on data mining based intrusion detection approaches which has been done belongs to the field of misuse detection in nature, association rules and frequent episodes mining aim to describe the intrusion signature, the ruler classifier was used to mainly detect intrusion behavior. NAIDS is the first data mining based anomaly detection system, the first intrusion detection system which lower false positive rate by classification engineering, the first intrusion detection system which put forward sliding windows techniques to carry out incremental, on-line mining. In principal, dynamic sliding window make NAIDS have the ability of real-time detection; classification engineering make NAIDS keep lower false positive rate, so in this sense, the approaches put forward in this dissertation can solve the most pressing problem faced by current IDS to great extent. A large amount experiments on DARPA 1998, 1999 was carried out and the validation and effectiveness of our approach were verified, which has guidance significance toward the following research work. Finally, the intrusion taxonomy was summarized in a systematical way, and the performance of NAIDS toward every type of attacks was given too. In general, NAIDS has better performance in detecting denial of service attacks and probe attacks.

Recommended Articles from the IT Science Category:

Most Viewed ScienceArticles in the IT Science Category:

  1. Channel Model Simulation and Spread Spectrum OFDM for HF Communication
  2. Study on the Political Function of Mass Media
  3. Research on Algorithms of GPU-Based 3D Medical Image Processing
  4. Research on QoS Based Multicast Routing Protocols in Mobile Ad Hoc Networks
  5. Study on Radar Tracking and Discrimination for Ballistic Missiles
  6. Study on Robot Joint Based on Reversing Ball Screw Mechanism
  7. Research on Real Time Pulse Train Deinterleaving for Radar Intercept System
  8. Reaearch on Optimization Problem of Manufacturing Process in a Discrete Manufacturing Industry
  9. Study of Parallel FDTD Algorithm and EM Scattering in Layered Half-space
  10. Spatial Three Degree-of-Freedom Parallel Mechanisms: Configurations, Performances and Applications
  11. The Application and Study of Electrochemical Biosensors Based on Nanomaterials
  12. Preparation and Investigation of p-ZnO Film and ZnO Light Emitting Device
  13. A Study of Space-Frequency Coding and Signal Detection in MIMO-OFDM Systems
  14. Research on Optical Fiber Sensor Based on Metal Nanoparticles
  15. Channel Estimation in MIMO-OFDM Wireless Communication System


© 2004-2009 Latest-Science-Articles.com - All Rights Reserved Worldwide.