Network intrusion detection by using multiple-criteria linear programming

G Kou,Y Peng,N Yan,Y Shi,ZX Chen,QM Zhu,J Huff,S McCartney
2004-01-01
Abstract:The early and reliable detection and deterrence of malicious attacks, both from external and internal sources is a crucial issue for today's e-business. There are various approaches available for intrusion detection; however, every method has its strengths and weaknesses. As a novel and promising data mining approach, multiple criteria linear programming (MCLP) has been successfully applied to credit card portfolio management for classifying two or multiple groups. The goal of this research is to determine the applicability of the MCLP algorithm to the intrusion detection problem. The demonstration of successful MCLP application in intrusion detection can add another option to network security toolbox. There are two objectives of this paper: first, apply MCLP to network intrusion detection system to identifying attacks; second, employ ensemble method to improve detection results. An overview of the two-group MCLP model formulation, the network intrusion, and the dataset used (KDD-99) in this paper are introduced first. Then MCLP is employed to KDD-99 and results are cross-validated. After that, the ensemble method is tested. As the results indicate, the ensemble method is better than cross-validated MCLP though the magnitude of the increase seems slight due the nature of the dataset.
What problem does this paper attempt to address?