Extracting IDS Rules from Honeypot Data: A Decision Tree Approach

Pedro Henrique Matheus, Leandro Nunes de Castro · International Conference on Information Security · 2014

This work uses data collected by honeypots to create rules and signatures for intrusion detection systems. The rules are extracted from decision trees constructed based on the data of a real honeypot installed on an internet connection without any filter. The results of the experiments showed that the extraction of rules for an intrusion detection system is possible using data mining techniques, in particular the decision tree algorithm. The technique proposed allows the analyst to summarize the data into a tree, where he/she can identify problems and extract rules to help reducing or even mitigate the security problems pointed out by the honeypot.

Read the paper · More papers on PaperTik