Research on Data Mining to System Log Audit Information in IDS

蒋嶷川,田盛丰
DOI: https://doi.org/10.3969/j.issn.1000-3428.2002.01.061
2002-01-01
Abstract:IDS (Intrusion Detection System) is a tool to detect the network intrusion actions. The key of IDS is the accuracy of the security mode rules. In network system there is a large amount of log audit data which contain much information related to security. So IDS can extract security mode rules from the log audit data. However, as the amount of the log audit date is too large, we can apply data mining technology into security mode rule extraction. This paper studies how to make data mining to system log audit information in IDS, provides the whole steps, and stresses using axis attribute to make character extraction to log audit information.
What problem does this paper attempt to address?