Anomaly Network Intrusion Detection System Based on Data Mining

宋世杰,胡华平,胡笑蕾,金士尧
2003-01-01
Abstract:The key issue of anomaly NIDS is building normal patterns, comparing current system or user behaviors with history behaviors, and then detecting intrusion. We introduced some data mining algorithms, presentd a classification method of IDS based on data mining, and described the process of data mining application in anomaly NIDS from network layer and application layer. We proposed three methods of pattern comparison in detail, and verified that the obtained normal audit data is enough for network layer anomaly NIDS.'
What problem does this paper attempt to address?