An Approach of Automatic Data Mining Algorithm for Intrusion Detection and Prevention System
Mr.A.Siles Balasingh · IOSR Journal of Computer Engineering · 2012
The Network security system plays a major role in the communication world, here every one's need security and assurance for their communication.Normally the hacking, Intrusion software's are using threats, malicious to enter in to the network and they are keep recording or monitoring the communication for this action the hackers may use following techniques Rexd, Rsh, Defult account/Null password, Generic Recon Mechanisms, NIS (Formerly yp), and Rpc Portmapper.The normal firewalls can address only insider threats.The main focus of our research is applied on two different platforms, the first one is processing on TCP-Dump portion using KDDCUP99 data set and mining, the second one is finding of best algorithm for data mining Intrusion on UNIX.From the available kddcup'99 dataset two subsets are taken with the record size of 997 and 11438.For UNIX User data all instances are taken.The classification rate and the false negative rate are used as the performance criteria with 3 fold cross validation.It is found that PART, SMO, Hyper pipes, Filtered Classifier, Random forest, Naïve Bayes Updateable, KStar are giving high classification rate with low false positive rate.For UNIX User data ZeroR is giving high performance.Real time data is also applied to finalize the best algorithm under each category of classifier.Later online implementation has to be done. I.