A Modular Data Mining Architecture for Intrusion Detection Systems' Data
Konstantinos Xynos, Andrew Blyth · 2008
Abstract: Many data mining architectures provide a solution to mining through the vast amounts of unprocessed knowledge. Few of these proposed solutions present the ability of intercommunication and data exchange. Data mining engines accept raw information as input and provide as output, results that can be used to make knowledgeable decisions. Since the output format may vary between each data mining engine, comparing and contrasting results usually requires a complicated unification process. This paper will present a high level architecture that provides solutions to the missing layer of unity between many different data mining architectures that are presented with interoperability issues. Communication between data mining engines and the proposed system will be conducted with the use of XML middleware. This will bring together the different components that will provide the facility to process requests before and/or after they reach a relational database. By conforming to the middleware the unification of the data is achieved in the initial stages and data miners can focus mining the data, not unifying it. The main system will include a number of core components, which will be available to the data mining engines. Distributed communication is achieved over the Simple Object Access Protocol (SOAP), which will support third party components, demonstrating the modularity of the system. The raw information that will be data mined will include intrusion events collected from multiple disparate Intrusion Detection Systems that have been unified and stored in a central database architecture. The XML middleware will provide a solution to the shortfalls of the current systems that do not sufficiently address interoperability, flexibility and conformity. Therefore, the proposed architecture will confirm the middleware’s strengths by validating the interoperability between the different components and the flexibility of the system with the introduction of third party components.