Identifying False Alarm for Network Intrusion Detection System Using Hybrid Data Mining and Decision Tree
Nor Badrul Anuar, and Hasimi Sallehudin, and Abdullah Ghani, and Omar Zakaria, (2008) Identifying False Alarm for Network Intrusion Detection System Using Hybrid Data Mining and Decision Tree. Malaysian Journal of Computer Science, 21 (2). pp. 110-115. ISSN 0127-9084 Official URL: http://ejum.fsktm.um.edu.my/ArticleInformation.aspx?ArticleID=673 AffiliationsUniversity of Malaya. Faculty of Computer Science & Information Technology Institut Tadbiran Awam Malaysia University of Malaya. Faculty of Computer Science & Information Technology University of Malaya. Faculty of Computer Science & Information Technology AbstractAlthough intelligent intrusion and detection strategies are used to detect any false alarms within the network critical segments of network infrastructures, reducing false positives is still a major challenge. Up to this moment, these strategies focus on either detection or response features, but often lack of having both features together. Without considering those features together, intrusion detection systems probably will not be able to highly detect on low false alarm rates. To offset the above mentioned constraints, this paper proposes a strategy to focus on detection involving statistical analysis of both attack and normal traffics based on the training data of KDD Cup 99. This strategy also includes a hybrid statistical approach which uses Data Mining and Decision Tree Classification. As a result, the statistical analysis can be manipulated to reduce misclassification of false positives and distinguish between attacks and false positives for the data of KDD Cup 99. Therefore, this strategy can be used to evaluate and enhance the capability of the IDS to detect and at the same time to respond to the threats and benign traffic in critical segments of network, application and database infrastructures. | Item Type: | Journal |
|---|
| Keywords: | False Positive, False Negative, Intrusion Detection, Data Mining, Decision Tree, Rule-Based |
|---|
| Subjects: | Q Science, Computer Science |
|---|
| ID Code: | 5023 |
|---|
Repository Staff Only: item control page
|