A New Approach to Intrusion Detection Based on Rough Set Theory

Cai Zhong · Chinese Journal of Computers · 2003

Intrusion detection is important in the defense in depth network security framework and a hot topic in computer network security in recent years. In this paper, an effective method for anomaly intrusion detection with low overhead and high efficiency is presented and applied to monitor the abnormal behavior of processes. The method is based on rough set theory and capable of extracting a set of detection rules with the minimum size to form a normal behavior model from the record of system call sequences generated during the normal execution of a process. It will detect the abnormal operating status of a process and thus report a possible intrusion. The normal behavior model in terms of the sequences of system calls is first defined and how to apply the rough set theory as a powerful data mining tool to establish the model is discussed by examples. The anomaly detection algorithm based on rough set theory is given in the paper. Compared with other methods, this method requires a smaller size of training data set, less efforts to collect training data and more suitable for real time detection. Experimental results show that this method is better than other methods reported in the literature in terms of detection resolution, required training data set and implementation for real time detection.

Read the paper · More papers on PaperTik