Network Threat Characterization in Multiple Intrusion Perspectives using Data Mining Technique

Oluwafemi Oriola · International Journal of Network Security & Its Applications · 2012

For effective security incidence response on the network, a reputable approach must be in place at both protected and unprotected region of the network.This is because compromise in the demilitarized zone could be precursor to threat inside the network.The improved complexity of attacks in present times and vulnerability of system are motivations for this work.Past and present approaches to intrusion detection and prevention have neglected victim and attacker properties despite the fact that for intrusion to occur, an overt act by an attacker and a manifestation, observable by the intended victim, which results from that act are required.Therefore, this paper presents a threat characterization model for attacks from the victim and the attacker perspective of intrusion using data mining technique.The data mining technique combines Frequent Temporal Sequence Association Mining and Fuzzy Logic.Apriori Association Mining algorithm was used to mine temporal rule patterns from alert sequences while Fuzzy Control System was used to rate exploits.The results of the experiment show that accurate threat characterization in multiple intrusion perspectives could be actualized using Fuzzy Association Mining.Also, the results proved that sequence of exploits could be used to rate threat and are motivated by victim properties and attacker objectives.

Read the paper · More papers on PaperTik