• DocumentCode
    590222
  • Title

    Detection of DoS attack time interval sequences on network traffic

  • Author

    Reshamwala, A. ; Mahajan, S.

  • Author_Institution
    Comput. Eng. Dept., SVKM´s NMIMS Univ., Mumbai, India
  • fYear
    2012
  • fDate
    Oct. 30 2012-Nov. 2 2012
  • Firstpage
    739
  • Lastpage
    744
  • Abstract
    As the total amount of traffic data in networks has been growing at an alarming rate, there is currently a substantial body of research that attempts to mine traffic data with the purpose of obtaining useful information. Many intrusions aren´t composed by single events, but a series of attack steps in chronological order. Analyzing the order in which events occur can improve the attack detection accuracy and reduce false alarms. This is because, very often, intrusion is a multi step process in which a number of events must occur sequentially in order to launch a successful attack. Therefore, sequential pattern mining algorithms are applied to intrusion detection to mine the order correlation about time sequential data, and then it can detect this kind of attack. Sequential pattern mining is an important data mining problem with broad applications. In this paper, we have implemented I-Apriori a candidate generation algorithm and I- PrefixSpan a pattern growth algorithm to detect time interval denial of service (DoS) attack sequences on network traffic data of KDD Cup 1999, 10 percent of training dataset, which is the annual Data Mining and Knowledge Discovery competition organized by ACM Special Interest Group on Knowledge Discovery and Data Mining, the leading professional organization of data miners. The comparison study is done on the number of patterns and on the average length of patterns obtained by varying the time interval of the sequential patterns.
  • Keywords
    data mining; security of data; sequential estimation; telecommunication security; telecommunication traffic; DoS attack; I-Apriori; I-PrefixSpan; KDD Cup 1999; attack detection accuracy; attack steps; data mining problem; false alarms; intrusion detection; network traffic data; order correlation; pattern growth algorithm; sequential pattern mining algorithms; sequential patterns; time interval denial of service attack sequences; time interval sequences; time sequential data; training dataset; Algorithm design and analysis; Classification algorithms; Computer crime; Data mining; Databases; Intrusion detection; Partitioning algorithms; Data mining; DoS attacks; Intrusion detection system; PrefixSpan; Sequential pattern; Time interval;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information and Communication Technologies (WICT), 2012 World Congress on
  • Conference_Location
    Trivandrum
  • Print_ISBN
    978-1-4673-4806-5
  • Type

    conf

  • DOI
    10.1109/WICT.2012.6409172
  • Filename
    6409172