J4

• Original Articles • Previous Articles     Next Articles

A data mining based design for the detection engine of the intrusion detection system

Lü Xi-xiang;YANG Bo;PEI Chang-xin;SU Xiao-long

  

  1. (State Key Lab. of Integrated Service Networks, Xidian Univ., Xi'an 710071, China)
  • Received:1900-01-01 Revised:1900-01-01 Online:2004-08-20 Published:2004-08-20

Abstract: We discuss our research in developing the detection engine of the intrusion detection system. The key ideas are to combine the slide window into the data mining technique to design the base detection engine which is the essential share of the meta detection engine. In addition, Apriori, a kind of data mining algorithm, is improved to mine network data. The improved algorithm does not scan all items in database and only links the items in the same list, so the detection efficiency is improved greatly. Also, other key details in IDS are put forward.

Key words: intrusion detection system, data mining, network security

CLC Number: 

  • TN915.08