Improving Intrusion Detection Through Merging Heterogeneous Ip Data

Wenjie Zhu,Qiang Wang
DOI: https://doi.org/10.1109/icinfa.2012.6246794
2012-01-01
Abstract:Intrusion Detection is an important and classical research area in network security. It is observed that existing intrusion detection methods usually research all data in the network as a whole. However, in reality, data in the network can be categorized into two types: upward IP data and downward IP data. These two types of IP data may play different roles in intrusion detection process. Based on this observation, a novel intrusion detection method called Duplex Traffic Joint Analyzing(DTJA) method is proposed so as to consider both upward and downward IP data more specifically. With this method, intrusion clues can be found more effectively and efficiently. Experiment results indicate this method is feasible.
What problem does this paper attempt to address?