Study of Adaptive Intrusion Detection with Data Mining

Fang Jinhe,Feng Yan,Wang Ruijie
DOI: https://doi.org/10.3321/j.issn:1002-8331.2006.18.048
2006-01-01
Abstract:After discussing the constraints of current intrusion detection systems(IDS),we issue two problems should be considered in developing an adaptive IDS,one is to select the time to update the normal profile and the other is to select a mechanism to update the profile.To resolve the first problem,we calculate the similarity between the incremental audit data and the normal profile and then decide whether to and when to update the profile.To resolve the second problem,we employ a sliding window approach and use only the audit data inside that sliding window to update the profile.The window therefore acts to filter out outdated audit data and to build a profile based on only recent data that reflects the recent system activities.
What problem does this paper attempt to address?