A Review of Data Mining based Intrusion Detection Techniques
Kamini Maheshwar, Divakar Singh · 2013
Traditional Data Mining techniques operate on structured data such as corporate databases; this has been an active area of research for many years. Intrusion detection is the process of monitoring and analyzing the events occurring in a computer system in order to detect signs of security problems. Intrusion detection is an area growing in relevance as more and more sensitive data are stored and processed in networked systems. An intrusion detection system (IDS) monitors networked devices and looks for anomalous or malicious behavior in the patterns of activity in the audit stream. A comprehensive ID requires a significant amount of human expertise and time for development. Data mining-based IDSs require less expert knowledge yet provide good performance. These systems are also capable of generalizing to new and unknown attacks. Data mining based intrusion Building an IDS is a complex task of knowledge engineering. In this paper we represent a survey of data mining based intrusion techniques. The data mining techniques are categorized based upon different approaches like association rule, classification techniques. The detection type is borrowed from intrusion detection as either misuse detection or anomaly detection. This paper provides the major advancement in the data mining based intrusion detection research using these approaches, the features and categories in the surveyed work.