Use of Data Mining in Enhancing IDS Based Security

Rajneesh Agrawal, Sandeep Kumar Sahu · 2013

An important problem in intrusion detection is how effectively can separate the attack patterns and normal data patterns from a large number of network data and how effectively generate automatic intrusion rules after collected raw network data. To accomplish this, various data mining techniques are used such as classification, clustering, association rule mining etc. Examples for Data Mining based Misuse detection model of IDS are JAM (Java Agents for Meta-learning), MADAM ID (Mining Audit Data for Automated Models for Intrusion Detection), and Automated Discovery of Concise Predictive Rules for Intrusion Detection. Ant clustering technique in data mining is a novel approach which uses Ants technique to find the relevant information and put them in various clusters. Since several Ants work in parallel therefore the processing speed of the system is high and in case of large data sets it is worth using Ant clustering to apply. This paper proposes to perform mining on the data collected from the IDS to enhance the speed of detection of intrusion with automatic detection using specific attributes of the intrusions. Various phases of the proposed work perform data collection, cleaning, clustering, detection and alarming system etc.

Read the paper · More papers on PaperTik