Refinement of rule-based intrusion detection system for denial of service attacks by support vector machine
Aki P. F. Chan, Wing W. Y. Ng, Daniel Yeung, Chi Ching Tsang · 2005
With the tremendous increase in connectivity and accessibility to the Internet, information security has become a serious global issue. Denial of service (DoS), one of the attacks evolved in recent years, has devastating effect to the commercial activities. We propose a hybrid intrusion detection system (HIDS) which incorporates the benefits of both rule-based and SVM techniques. In brief, the SVM is used to select important features and generate rules, while the rule-based system is then applied to detect the DoS attacks. The rule set generated by the HIDS is more accurate and compact. Experimental results show that the HIDS has a better performance than the rule-based system with rules extracted only from human experts.