JOURNAL ARTICLE

Network intrusion detection system model based on data mining

Abstract

The paper's object is to develop a network intrusion detection model based on data mining technology, which can detect known intrusion effectively and has a good capacity to recognize unknown data schema which can't be detected effectively in traditional IDS. The paper mainly does the following work: by analyzing the intrusion deeply, extract the properties which can reflect intrusion characteristics effectively; combine misuse detection, anomaly detection and human intervention, establish rule library based on C.45 decision tree algorithm and use the optimal pattern matching so as to improve detection rate; the hosts are clustered to be IP group based on visit number by k-means clustering algorithm, the audit data are divided into parts under the IP group's direction, and the classifiers are built up by divided audit data respectively, then the detected Data apply different rules according to their own IP group, thereby reduce false positives. The experiments proved that the method is effective to detect intrusion such as scanning and Deny of Service.

Keywords:
Intrusion detection system Computer science Data mining Anomaly-based intrusion detection system Cluster analysis False positive paradox Schema (genetic algorithms) Anomaly detection Decision tree Pattern matching Network security Artificial intelligence Machine learning Computer network

Metrics

23
Cited By
3.88
FWCI (Field Weighted Citation Impact)
8
Refs
0.94
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

Network Security and Intrusion Detection
Physical Sciences →  Computer Science →  Computer Networks and Communications
Network Packet Processing and Optimization
Physical Sciences →  Computer Science →  Hardware and Architecture
Internet Traffic Analysis and Secure E-voting
Physical Sciences →  Computer Science →  Artificial Intelligence

Related Documents

© 2026 ScienceGate Book Chapters — All rights reserved.