Design & Implementation of Distributed Network Intelligent Intrusion Detection System Model
Chang Xin-tan · Journal of Xi'an University of Technology · 2008
A model of intelligent intrusion detection system for distributed network is designed in this paper.In this model,a fast clustering algorithm for mixed data and rules mining algorithm based on constrained attribute are adopted.They are used to classify and associate every IDS's original data intelligently;and an intrusion pattern library used for real-time detection in different network segments is established.In the center of data fusion,a data fusion method based on D-S evidence theory is adopted to deal with original alarms coming from different IDS,and to create high-level ones whereby inhibiting a sea of alarm warnings effectively.The experimental results show that this method can eliminate repeated alarms,reduce the rate of false alarms,improve the amount of alarm information,and provide a whole view of network security for administrators.