• DocumentCode
    3337543
  • Title

    Network anomaly detection tools based on association rules

  • Author

    Othman, Zulaiha Ali ; Eljadi, E.E.

  • Author_Institution
    Sch. of Comput. Sci., Univ. Kebangsaan Malaysia, Bangi, Malaysia
  • fYear
    2011
  • fDate
    17-19 July 2011
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    With the growth of computer networks, the number of attacks posing serious security risks for networks has grown extensively. Many organizations are faced with the problem of detecting whether or not they have an anomaly in their network transactions. The Network Intrusion Detection System (NIDS) is one of the popular tools used to secure and protect networks. In order to secure a network the signature rules in NIDS should be updated with the latest signature detection rule. Therefore, this research aims to develop a network anomaly detection tool which focuses on association rule data mining techniques to detect anomalies and also produce anomaly detection rules. The tool, named as NASSR, consists of the following functions: pre-processing of the raw data network transaction that is captured using Wireshark and transforming the data into three types of data sets (2, 5 and 10 seconds), normalization (min., max.) and mining (Appriori, Fuzzy Appriori, and FP-Growth). The anomaly detection is calculated by comparing it with a normal network data set, which is validated by CACE tools. The data set is determined as having no intrusion, if the similarity results are higher than the user threshold, and vice versa. This paper also presents the interface tools used to analyse the 7GB real network data set obtained from Pusat Teknologi Maklumat (PTM), Universiti Kebangsaan Malaysia (UKM), which consists of three days´ accumulation of network traffic data, and presents the data sets that have anomalies and their rules. The best result shows that the best technique for pre-processing is in the form of two seconds. Fuzzy Appriori presents the most accurate result while FP-growth has been shown as a faster mining technique. The tools can be easily used to detect anomalies for any network traffic.
  • Keywords
    computer network security; data mining; CACE tools; FP-growth; NASSR; Pusat Teknologi Maklumat; Universiti Kebangsaan Malaysia; Wireshark; association rule data mining techniques; computer networks; data network transaction preprocessing; data transformation; fuzzy apriori; interface tools; network anomaly detection tools; network intrusion detection system; signature detection rule; Association rules; IP networks; Intrusion detection; Itemsets; User interfaces; Association Rules Techniques; Data Mining; network intrusion detection system (NIDS);
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Electrical Engineering and Informatics (ICEEI), 2011 International Conference on
  • Conference_Location
    Bandung
  • ISSN
    2155-6822
  • Print_ISBN
    978-1-4577-0753-7
  • Type

    conf

  • DOI
    10.1109/ICEEI.2011.6021705
  • Filename
    6021705