Research of Anomaly Detection System Based on Data Mining

吕志军,袁卫忠,仲海骏,黄皓,曾庆凯,谢立
DOI: https://doi.org/10.3969/j.issn.1002-137x.2004.10.015
2004-01-01
Computer Science
Abstract:Intrusion detection system(IDS)must be capable of detecting new and unknown attacks. In this paper, we propose an Anomaly Detection System based on Data Mining(ADESDM). Firstly, ADESDM mine suspicious behaviors in the protocol header, ports and application data with strong association rules and weak association rules; then, it sends the suspicious behaviors to the Deciding Module based on Bayesian Belief Net (DMBBN). In real network communications, the attributes, such as time, direction, ports and IP addresses, are influencing each other. The DMBBN illustrates the conditional probabilities and relationship among the above attributes, and uses them to determine whether the suspicious behaviors are normal ones or attacks. Thus, system can reduce the false alarm rate.
What problem does this paper attempt to address?