Title of article :
A proposed HTTP service based IDS
Author/Authors :
Abd-Eldayem, Mohamed M. Cairo University - Faculty of Computers and Information - IT Department, Egypt , Abd-Eldayem, Mohamed M. King Saud University - College of Computers and Information Sciences - CEN Department, Saudi Arabia
From page :
13
To page :
24
Abstract :
The tremendous growth of the web-based applications has increased information security vulnerabilities over the Internet. Security administrators use Intrusion-Detection System (IDS) to monitor network traffic and host activities to detect attacks against hosts and network resources. In this paper IDS based on Naıve Bayes classifier is analyzed. The main objective is to enhance IDS performance through preparing the training data set allowing to detect malicious connections that exploit the http service. Results of application are demonstrated and discussed. In the training phase of the proposed IDS, at first a feature selection technique based on Naı¨ve Bayes classifier is used, this technique identifies the most important HTTP traffic features that can be used to detect HTTP attacks. In the testing and running phases proposed IDS classifies the network traffic based on the requested service, then based on the selected features Naıve Bayes classifier is used to analyze the HTTP service based traffic and identifies the HTTP normal connections and attacks. The performance of the IDS is measured through experiments using NSL-KDD data set. The results show that the detection rateof the IDS is about 99%, the false-positive rate is about1%, and the false-negative rate is about 0.25%; therefore, proposed IDS holds the highest detection rate and the lowest false alarm compared with other leading IDS. In addition, the proposed IDS based on Naı¨ve Bayes is used to classify network connections as a normal or attack. And it holds a high detection rate and a low false alarm.
Keywords :
Computer security , Network security , Intrusion Detection System(IDS) , Naıve Bayes classifier
Journal title :
Egyptian Informatics Journal
Journal title :
Egyptian Informatics Journal
Record number :
2620927
Link To Document :
بازگشت