DocumentCode :
2676170
Title :
Two Stratum Bayesian Network Based Anomaly Detection Model for Intrusion Detection System
Author :
Huijuan, Lu ; Jianguo, Chen ; Wei, Wei
Author_Institution :
Dept. of Comput. Sci. & Technol., China Jiliang Univ., Hangzhou
fYear :
2008
fDate :
3-5 Aug. 2008
Firstpage :
482
Lastpage :
487
Abstract :
An intrusion detection system (IDS) attempts to identify attacks by comparing collected data to predefined signatures known to be malicious (signature-based IDS) or to a model of legal behaviour (anomaly-based IDS). Anomaly-based approaches have the advantage of being able to detect previously unknown attacks, but they suffer from the difficulty of building robust models of acceptable behaviour which may result in a large number of false alarms. Two reasons for the large number of false alarms, caused by incorrect classification of events in current systems, one is the simplistic aggregation of model outputs inthe decision phase. The other reason is the lack of integration of additional information into the decision process. To mitigate these shortcomings, this paper proposes a two stratum Bayesian networks based anomaly detection and decision model for intrusion detection system. Bayesian networks improve the aggregation of outputs, such as empirical data and allow one to seamlessly incorporate additional information. Experimental results clearly demonstrate the efficiency of our approach to improve the accuracy of the intrusion detection and decision process in an anomaly based IDS.
Keywords :
Bayes methods; security of data; anomaly detection model; decision process; false alarms; incorrect event classification; intrusion detection system; two stratum Bayesian network; Bayesian methods; Computer science; Computer security; Data security; Electronic commerce; Intrusion detection; Law; Legal factors; Robustness; Telecommunication traffic; Anomaly detection; Bayesian networks; Intrusion detection;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Electronic Commerce and Security, 2008 International Symposium on
Conference_Location :
Guangzhou City
Print_ISBN :
978-0-7695-3258-5
Type :
conf
DOI :
10.1109/ISECS.2008.178
Filename :
4606112
Link To Document :
بازگشت