DocumentCode :
2841756
Title :
Anomaly Based Network Intrusion Detection with Unsupervised Outlier Detection
Author :
Zhang, Jiong ; Zulkernine, Mohammad
Author_Institution :
School of Computing, Queen´´s University, Kingston, Ontario, Canada K7L 3N6. zhang@cs.queensu.ca
Volume :
5
fYear :
2006
fDate :
38869
Firstpage :
2388
Lastpage :
2393
Abstract :
Anomaly detection is a critical issue in Network Intrusion Detection Systems (NIDSs). Most anomaly based NIDSs employ supervised algorithms, whose performances highly depend on attack-free training data. However, this kind of training data is difficult to obtain in real world network environment. Moreover, with changing network environment or services, patterns of normal traffic will be changed. This leads to high false positive rate of supervised NIDSs. Unsupervised outlier detection can overcome the drawbacks of supervised anomaly detection. Therefore, we apply one of the efficient data mining algorithms called random forests algorithm in anomaly based NIDSs. Without attack-free training data, random forests algorithm can detect outliers in datasets of network traffic. In this paper, we discuss our framework of anomaly based network intrusion detection. In the framework, patterns of network services are built by random forests algorithm over traffic data. Intrusions are detected by determining outliers related to the built patterns. We present the modification on the outlier detection algorithm of random forests. We also report our experimental results over the KDD´99 dataset. The results show that the proposed approach is comparable to previously reported unsupervised anomaly detection approaches evaluated over the KDD´ 99 dataset.
Keywords :
Access control; Computer networks; Cryptography; Data mining; Data security; Detection algorithms; Information security; Intrusion detection; Telecommunication traffic; Training data;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Communications, 2006. ICC '06. IEEE International Conference on
Conference_Location :
Istanbul
ISSN :
8164-9547
Print_ISBN :
1-4244-0355-3
Electronic_ISBN :
8164-9547
Type :
conf
DOI :
10.1109/ICC.2006.255127
Filename :
4024522
Link To Document :
بازگشت