Using Decision Trees to Extract IDS Rules from Honeypot Data
Pedro Henrique Matheus da Costa Ferreira, The Society of Digital Information and Wireless Communication · International Journal of Cyber-Security and Digital Forensics · 2015
It has been almost two decades since the first honeypot was proposed. Despite that, although there are several studies involving network traffic data, few are those dedicated to extract knowledge from honeypot data. The present paper uses data collected by honeypots to create rules and signatures for intrusion detection systems. The rules are extracted from decision trees constructed based on the data of real honeypots installed on internet connections without any filter. The results of the experiments showed that the extraction of rules for an intrusion detection system is possible using data mining techniques, in particular decision trees. The technique proposed allows the analyst to summarize the data into a tree, where he/she can identify problems and extract rules to help reducing or even mitigate the security problems pointed out by the honeypot.