Intrusion detection based on decision tree with mutual information

Wenli Li · Journal of Liaoning Technical University · 2009

Traditional intrusion detection systems(IDS) not only have high rate of false positive and false negative with the increasing complexity of intrusion,but also lack effectiveness for very large test data because of its simple structure.Therefore,based on relationship of the attributes of intrusion rules,this paper presents a new classification algorithm in order to improve speed and accuracy of intrusion detection,which selects a node's attribute with more information gain,but with less mutual information between the attributes of the node and that of all the upper nodes.This method avoids selecting the redundant attributes and achieves the reduction in entropy.After the algorithm is designed and analyzed,Apply it into the rules to form a decision tree,which changes the conventional way of searching the packet orderly,and improves the matching speed at the cost of preprocess time.The result of an experiment shows that the intrusion detection system using the proposed algorithm works more efficiency than using conventional method or ID3 decision tree.

Read the paper · More papers on PaperTik