DocumentCode
3337543
Title
Network anomaly detection tools based on association rules
Author
Othman, Zulaiha Ali ; Eljadi, E.E.
Author_Institution
Sch. of Comput. Sci., Univ. Kebangsaan Malaysia, Bangi, Malaysia
fYear
2011
fDate
17-19 July 2011
Firstpage
1
Lastpage
7
Abstract
With the growth of computer networks, the number of attacks posing serious security risks for networks has grown extensively. Many organizations are faced with the problem of detecting whether or not they have an anomaly in their network transactions. The Network Intrusion Detection System (NIDS) is one of the popular tools used to secure and protect networks. In order to secure a network the signature rules in NIDS should be updated with the latest signature detection rule. Therefore, this research aims to develop a network anomaly detection tool which focuses on association rule data mining techniques to detect anomalies and also produce anomaly detection rules. The tool, named as NASSR, consists of the following functions: pre-processing of the raw data network transaction that is captured using Wireshark and transforming the data into three types of data sets (2, 5 and 10 seconds), normalization (min., max.) and mining (Appriori, Fuzzy Appriori, and FP-Growth). The anomaly detection is calculated by comparing it with a normal network data set, which is validated by CACE tools. The data set is determined as having no intrusion, if the similarity results are higher than the user threshold, and vice versa. This paper also presents the interface tools used to analyse the 7GB real network data set obtained from Pusat Teknologi Maklumat (PTM), Universiti Kebangsaan Malaysia (UKM), which consists of three days´ accumulation of network traffic data, and presents the data sets that have anomalies and their rules. The best result shows that the best technique for pre-processing is in the form of two seconds. Fuzzy Appriori presents the most accurate result while FP-growth has been shown as a faster mining technique. The tools can be easily used to detect anomalies for any network traffic.
Keywords
computer network security; data mining; CACE tools; FP-growth; NASSR; Pusat Teknologi Maklumat; Universiti Kebangsaan Malaysia; Wireshark; association rule data mining techniques; computer networks; data network transaction preprocessing; data transformation; fuzzy apriori; interface tools; network anomaly detection tools; network intrusion detection system; signature detection rule; Association rules; IP networks; Intrusion detection; Itemsets; User interfaces; Association Rules Techniques; Data Mining; network intrusion detection system (NIDS);
fLanguage
English
Publisher
ieee
Conference_Titel
Electrical Engineering and Informatics (ICEEI), 2011 International Conference on
Conference_Location
Bandung
ISSN
2155-6822
Print_ISBN
978-1-4577-0753-7
Type
conf
DOI
10.1109/ICEEI.2011.6021705
Filename
6021705
Link To Document