A new combined strategy to intrusion detection
Adesina S. Sodiya, H.O.D. Longe · Journal of Applied Computer Science · 2004
Several techniques have been used in designing Intrusion Detection Systems (IDS), which monitors computer-based systems for any set of actions that attempt to compromise the integrity, confidentiality or availability of computer resources. However, none could be considered to be sufficiently effective in terms of detecting intrusions and elimination of false alarms. In this work, an approach combining data mining and expert system techniques is used to design a more effective anomaly-based IDS. The approach involves mining system's audit data to determine consistent and useful patterns of users' behaviours, and then profiling these patterns. Expert system is then applied to detect anomalies and prompt alarms. The evaluation of the intrusion detection system based on this novel approach shows significant improvement in terms of detection efficiency and 1. false alarm rate when compared with other known methods in the literature.