MACHINE LEARNING APPROACHES FOR NETWORK INTRUSION DETECTION: A SURVEY

覃爱明,胡昌振,谭惠民
DOI: https://doi.org/10.3969/j.issn.1009-6094.2001.01.007
2001-01-01
Applied Mechanics and Materials
Abstract:With the developement of network technology and network connection scales, network security has already been an important research task. In this regard it is imperative to detect those unseen system attacks in an automated monitoring environment. As a new kind of network security technology, network intrusion detection seeks to detect attacks in an organization's security policy quite simply. However, existing intrusion detection systems rely heavily on human analysts to differentiate intrusive from non-intrusive network traffic. For such purpose machine learning techniques are used to provide decision aids for the analysts and automatically generate rules for computer network intrusion detection. Machine learning can be viewed as the attempt to build computer programs that improve performance of some task though learning and experience. This investigation goes back to the middle of 1990's. The present review gives a brief introduction to 6 kinds of machine learning approaches for network intrusion detection system, namely, Data Mining, Neural Networks, Genetic Algorithms, Decision Trees, Rough Sets and Immune System-Based Approach. Their principles and learning processes are presented in details. On the basis of the introduction , the respective advantages and disadvantages are commented. In the end, the developing directions of machine learning techniques are addressed according to the application requirements of network intrusion detection system.
What problem does this paper attempt to address?