Rule miner of intrusion detection system
Bing Xiong · Journal of Changsha University of Science & Technology · 2011
A novel rule miner method was proposed for Snort network-based intrusion detection system(NIDS).This method firstly wish to help the Snort NIDS to automatically generate rules from detection attack data,and implement the ability of detection novel and abnormal attack behaviors.On the other hand,a rule miner module is implemented by applying data mining technique to extract new attack rules from attack packages collected,and convert the patterns to Snort detection rules for on-line intrusion detection.The experimental results on KDD-99 dataset show that the proposed method is suitable for real-time rule mining,and outperforms other classifier methods by providing the highest detection accuracy for intrusion attacks and low false rate for normal network traffic.