Using Data Mining Techniques in Building Dataset for Network Intrusion Detection

Manar Jacob Aljabr · International Review on Computers and Software (IRECOS) · 2015

In this paper we will implement a software component for filtering rough network traffic to extract TCP traffic, and process it into structured connection records using data mining techniques to build a training data set; consisting of multi features items and usable in detecting some types of DOS (Denial of service) attacks like SynFlood attack; when the destination is flooded by connection requests via spoofed IP addresses within a small time window. This data set would be formatted with ARFF format and used in evaluating some classification algorithms implemented in WEKA machine learning framework to extract the best detection model for the purpose of improving the efficiency of network intrusion detection within audit trails.

Read the paper · More papers on PaperTik