Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree

Although intelligent intrusion and detection strategies are used to detect any false alarms within the network critical segments of network infrastructures, reducing false positives is still a major challenge. Up to this moment, these strategies focus on either detection or response features, but of...

Full description

Bibliographic Details
Main Authors: Anuar, N.B., Sallehudin, H., Gani, Abdullah, Zakari, O.
Format: Article
Language:English
Published: 2008
Subjects:
Online Access:http://eprints.um.edu.my/4497/1/2008_Identifying_false_alarm_for_Network_Intrusion_Detection_Sysytem_Using_Hybrid_Data_Mining_and_Decision_Tree.pdf
_version_ 1825718950333251584
author Anuar, N.B.
Sallehudin, H.
Gani, Abdullah
Zakari, O.
author_facet Anuar, N.B.
Sallehudin, H.
Gani, Abdullah
Zakari, O.
author_sort Anuar, N.B.
collection UM
description Although intelligent intrusion and detection strategies are used to detect any false alarms within the network critical segments of network infrastructures, reducing false positives is still a major challenge. Up to this moment, these strategies focus on either detection or response features, but often lack of having both features together. Without considering those features together, intrusion detection systems probably will not be able to highly detect on low false alarm rates. To offset the abovementioned constraints, this paper proposes a strategy to focus on detection involving statistical analysis of both attack and normal traffics based on the training data of KDD Cup 99. This strategy also includes a hybrid statistical approach which uses Data Mining and Decision Tree Classification. As a result, the statistical analysis can be manipulated to reduce misclassification of false positives and distinguish between attacks and false positives for the data of KDD Cup 99. Therefore, this strategy can be used to evaluate and enhance the capability of the IDS to detect and at the same time to respond to the threats and benign traffic in critical segments of network, application and database infrastructures.
first_indexed 2024-03-06T05:12:07Z
format Article
id um.eprints-4497
institution Universiti Malaya
language English
last_indexed 2024-03-06T05:12:07Z
publishDate 2008
record_format dspace
spelling um.eprints-44972018-10-11T09:25:37Z http://eprints.um.edu.my/4497/ Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree Anuar, N.B. Sallehudin, H. Gani, Abdullah Zakari, O. T Technology (General) Although intelligent intrusion and detection strategies are used to detect any false alarms within the network critical segments of network infrastructures, reducing false positives is still a major challenge. Up to this moment, these strategies focus on either detection or response features, but often lack of having both features together. Without considering those features together, intrusion detection systems probably will not be able to highly detect on low false alarm rates. To offset the abovementioned constraints, this paper proposes a strategy to focus on detection involving statistical analysis of both attack and normal traffics based on the training data of KDD Cup 99. This strategy also includes a hybrid statistical approach which uses Data Mining and Decision Tree Classification. As a result, the statistical analysis can be manipulated to reduce misclassification of false positives and distinguish between attacks and false positives for the data of KDD Cup 99. Therefore, this strategy can be used to evaluate and enhance the capability of the IDS to detect and at the same time to respond to the threats and benign traffic in critical segments of network, application and database infrastructures. 2008 Article PeerReviewed application/pdf en http://eprints.um.edu.my/4497/1/2008_Identifying_false_alarm_for_Network_Intrusion_Detection_Sysytem_Using_Hybrid_Data_Mining_and_Decision_Tree.pdf Anuar, N.B. and Sallehudin, H. and Gani, Abdullah and Zakari, O. (2008) Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree. Malaysian Journal of Computer Science, 21 (2). pp. 101-115. ISSN 0127-9084, http://wseas.us/e-library/conferences/2008/bucharest2/dncoco/dncoco03.pdf
spellingShingle T Technology (General)
Anuar, N.B.
Sallehudin, H.
Gani, Abdullah
Zakari, O.
Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
title Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
title_full Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
title_fullStr Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
title_full_unstemmed Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
title_short Identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
title_sort identifying false alarm for network intrusion detection system using hybrid data mining and decision tree
topic T Technology (General)
url http://eprints.um.edu.my/4497/1/2008_Identifying_false_alarm_for_Network_Intrusion_Detection_Sysytem_Using_Hybrid_Data_Mining_and_Decision_Tree.pdf
work_keys_str_mv AT anuarnb identifyingfalsealarmfornetworkintrusiondetectionsystemusinghybriddatamininganddecisiontree
AT sallehudinh identifyingfalsealarmfornetworkintrusiondetectionsystemusinghybriddatamininganddecisiontree
AT ganiabdullah identifyingfalsealarmfornetworkintrusiondetectionsystemusinghybriddatamininganddecisiontree
AT zakario identifyingfalsealarmfornetworkintrusiondetectionsystemusinghybriddatamininganddecisiontree