Implementation of sequence patterns mining in network intrusion detection system
Yang Xiang-Rong, Qinbao Song, Shen Jun-Yi · 2002
In this paper we present a frequent sequence pattern mining-based algorithm used for network intrusion detection, which is an application and extension of the SPADE algorithm. It is based on the idea that much behavior on the network appears as sequences of activities, according to the sequence patterns we computed, we can construct the intrusion rule base and legal action rule base, then we can detect known and novel intrusion activities by rule matching. In addition, when the system is running, we use an incremental sequence pattern mining algorithm to complement the rule library in order to avoid re-executing the algorithm on the entire dataset, thereby reducing execution time. The experimental results indicate that this algorithm is efficient enough to meet the needs for active detection of intrusion. Compared with most existing methods used in commercial systems which are built using purely knowledge engineering approaches, our algorithm is more intelligent and adaptive.