Title :
Detection of DoS attack time interval sequences on network traffic
Author :
Reshamwala, A. ; Mahajan, S.
Author_Institution :
Comput. Eng. Dept., SVKM´s NMIMS Univ., Mumbai, India
fDate :
Oct. 30 2012-Nov. 2 2012
Abstract :
As the total amount of traffic data in networks has been growing at an alarming rate, there is currently a substantial body of research that attempts to mine traffic data with the purpose of obtaining useful information. Many intrusions aren´t composed by single events, but a series of attack steps in chronological order. Analyzing the order in which events occur can improve the attack detection accuracy and reduce false alarms. This is because, very often, intrusion is a multi step process in which a number of events must occur sequentially in order to launch a successful attack. Therefore, sequential pattern mining algorithms are applied to intrusion detection to mine the order correlation about time sequential data, and then it can detect this kind of attack. Sequential pattern mining is an important data mining problem with broad applications. In this paper, we have implemented I-Apriori a candidate generation algorithm and I- PrefixSpan a pattern growth algorithm to detect time interval denial of service (DoS) attack sequences on network traffic data of KDD Cup 1999, 10 percent of training dataset, which is the annual Data Mining and Knowledge Discovery competition organized by ACM Special Interest Group on Knowledge Discovery and Data Mining, the leading professional organization of data miners. The comparison study is done on the number of patterns and on the average length of patterns obtained by varying the time interval of the sequential patterns.
Keywords :
data mining; security of data; sequential estimation; telecommunication security; telecommunication traffic; DoS attack; I-Apriori; I-PrefixSpan; KDD Cup 1999; attack detection accuracy; attack steps; data mining problem; false alarms; intrusion detection; network traffic data; order correlation; pattern growth algorithm; sequential pattern mining algorithms; sequential patterns; time interval denial of service attack sequences; time interval sequences; time sequential data; training dataset; Algorithm design and analysis; Classification algorithms; Computer crime; Data mining; Databases; Intrusion detection; Partitioning algorithms; Data mining; DoS attacks; Intrusion detection system; PrefixSpan; Sequential pattern; Time interval;
Conference_Titel :
Information and Communication Technologies (WICT), 2012 World Congress on
Conference_Location :
Trivandrum
Print_ISBN :
978-1-4673-4806-5
DOI :
10.1109/WICT.2012.6409172