DocumentCode
2124436
Title
Local Area Network Anomaly Detection Using Association Rules Mining
Author
Li, Xiaolei ; Zhang, Yun ; Li, Xun
Author_Institution
Res. Center of Spatial Inf. & Digital Eng., Wuhan Univ., Wuhan, China
fYear
2009
fDate
24-26 Sept. 2009
Firstpage
1
Lastpage
5
Abstract
In a local area network (LAN) where users are relatively stable, the usage patterns of systems and working habits are also stable. This character implies that there exist many rules in corresponding network applications. By intercepting all the frames in the LAN and pre-processing the collected data, association rules mining techniques can be used to extract association rules from the network data. These rules can latter be effectively applied to network anomaly detection in the LAN. This paper discusses the method of using association rules mining in anomaly detection of LAN, and analyzes its working principle. We give a detailed discussion on several steps, including the method of data acquisition and preprocessing, association rules mining, the usage of similarity to determine whether the network behavior conform to the extracted association rules and the detection of anomalous behaviors. Finally, the corresponding experimental results are given.
Keywords
data acquisition; data mining; local area networks; security of data; association rules mining; data acquisition; data preprocessing; local area network anomaly detection; Association rules; Data acquisition; Data mining; Event detection; Information security; Intelligent networks; Libraries; Local area networks; Network servers; Protection;
fLanguage
English
Publisher
ieee
Conference_Titel
Wireless Communications, Networking and Mobile Computing, 2009. WiCom '09. 5th International Conference on
Conference_Location
Beijing
Print_ISBN
978-1-4244-3692-7
Electronic_ISBN
978-1-4244-3693-4
Type
conf
DOI
10.1109/WICOM.2009.5302952
Filename
5302952
Link To Document