Network-based Intrusion Detection System Using Rough Set
Hongmei Zhang · Jisuanji gongcheng · 2006
Most of current products and models are poor at detecting novel attacks without an acceptable level of accuracy or false alarms.In order to figure out this problem,a network based intrusion detection system is established,and many up-to-date attack tools are used to attack the network.On the basis of the intrusion experiment,29 variables are chosen as intrusion features to characterize the status of network connection.At the same time,the rough sets theory is exploited as a detector of network connection.The experimental results indicate that the features extracted from network connection are good indicators of the status of network and the rough sets theory is powerful in multi-class classification as well as effective in unknown attack detection.