Title :
Two Stratum Bayesian Network Based Anomaly Detection Model for Intrusion Detection System
Author :
Huijuan, Lu ; Jianguo, Chen ; Wei, Wei
Author_Institution :
Dept. of Comput. Sci. & Technol., China Jiliang Univ., Hangzhou
Abstract :
An intrusion detection system (IDS) attempts to identify attacks by comparing collected data to predefined signatures known to be malicious (signature-based IDS) or to a model of legal behaviour (anomaly-based IDS). Anomaly-based approaches have the advantage of being able to detect previously unknown attacks, but they suffer from the difficulty of building robust models of acceptable behaviour which may result in a large number of false alarms. Two reasons for the large number of false alarms, caused by incorrect classification of events in current systems, one is the simplistic aggregation of model outputs inthe decision phase. The other reason is the lack of integration of additional information into the decision process. To mitigate these shortcomings, this paper proposes a two stratum Bayesian networks based anomaly detection and decision model for intrusion detection system. Bayesian networks improve the aggregation of outputs, such as empirical data and allow one to seamlessly incorporate additional information. Experimental results clearly demonstrate the efficiency of our approach to improve the accuracy of the intrusion detection and decision process in an anomaly based IDS.
Keywords :
Bayes methods; security of data; anomaly detection model; decision process; false alarms; incorrect event classification; intrusion detection system; two stratum Bayesian network; Bayesian methods; Computer science; Computer security; Data security; Electronic commerce; Intrusion detection; Law; Legal factors; Robustness; Telecommunication traffic; Anomaly detection; Bayesian networks; Intrusion detection;
Conference_Titel :
Electronic Commerce and Security, 2008 International Symposium on
Conference_Location :
Guangzhou City
Print_ISBN :
978-0-7695-3258-5
DOI :
10.1109/ISECS.2008.178