Misuse Detection Using Hybrid of Association Rule Mining and Connectionist Modeling
Mansour Sheikhan, Zahra Jadidi · 2009
With the growing of computer networks, the number of attacks has grown extensively. Intrusion detection system (IDS) is known as a critical technology to help protection. In this paper, a hybrid misuse- based IDS, using combined structure of an association rule mining algorithm and a connectionist model, is presented. The key idea is to take advantage of different classification abilities of knowledge -based and machine learning approaches for different attacks. To lower the computational load of association rule mining, the inputs of rule mining algorithm are selected based on the results of a feature relevance analysis. Experimental results show that the proposed hybrid model, in which knowledge-based section of the system reports hard recognizable attack categories, can improve classification results, especially for remote-to-local (R2L) and user-to-root (U2R) attack classes. This hybrid system also offers better detection rate (DR) and cost per example (CPE) compared to neural -based IDS. False alarm rate (FAR) of the proposed model is comparable with other intrusion detection systems, as well.