A Time Series Data Mining Based on ARMA and Hopfield Model for Intrusion Detection

Tianqi Yang
DOI: https://doi.org/10.1109/ICNNB.2005.1614797
2005-01-01
Abstract:Given the widespread use of modern information technology, a large number of time series may be collected during network security applications. The paper use a computer and network security as a case to illustrate how data mining can be applied to such time series, and help network intrusion detection reap the benefits of such an effort. Instead of a traditional approach of principal component analysis (PCA), nature moving average (ARMA) and Hopfield models are employed to analyze the time series. To illustrate the feasibility and simplicity of the above procedures for time series data mining, the problem of measuring normality in HTTP traffic for the purpose of anomaly-based network intrusion detection is addressed. The detection results provided by our approach show important improvements, both in detection ratio and regarding false alarms, in comparison with those obtained using other current techniques
What problem does this paper attempt to address?