SVM Classification-Based Intrusion Detection System

陈光英,张千里,李星
DOI: https://doi.org/10.3321/j.issn:1000-436x.2002.05.010
2002-01-01
Abstract:An intrusion detection system based on SVM classification technique was designed and implemented. It uses the technique of support vector machine to recognize TCP network connections without the reference of the port numbers. If a connection is recognized in a category that is different from the type of service characterized by the port number, then the connection is considered abnormal. This paper also focused on how the trace time, the feature set size and the kernel function of SVM affect the recognition error rate. Results from preliminary experiments show that our system can detect abnormal TCP network connections.
What problem does this paper attempt to address?