Improved signature based intrusion detection using clustering rule for decision tree
Phuong Do, Ho-Seok Kang, Sung‐Ryul Kim · 2013
Malicious network data are becoming more and more serious nowadays. To deal with this problem, IDSs are used popularly as a security technology that helps to discover, determine and identify unauthorized use of information systems. However, the attacking technologies are becoming more complicated and require more time to detect. In order to make sure that IDS can work efficiently and accurately, novel algorithms need to be applied to adapt to the quick change of attacking technologies. There are many algorithms that are proposed to work on the matching process. Kruegel et al. generated a decision tree that is utilized to find malicious input items using as few redundant comparisons as possible [1].