Anomaly and Missuses Detection Using IDS Technique
Anu Devi · International Journal for Research in Applied Science and Engineering Technology · 2017
In the recent years, as the second line of defense after firewall, the intrusion detection technique has got fast development. a mixture of data mining techniques such as clustering, categorization and association rule detection are being used for intrusion detection This research proposed IDS using cloud computing by integrated signature based (Snort) with abnormality based (Naive Bayes) to enhance system security to detect attacks. This research used Knowledge Discovery Data Mining (KDD) CUP 20 dataset and Waikato Environment for Knowledge Analysis (WEKA) program for testing the proposed hybrid IDS. Accuracy, detection rate, time to construct model and false alarm rate were used as parameters to evaluate performance with Naïve Bayes, Snort with J48graft and Snort Keywords: Data Mining, IDS, KDD, Native Bays I. INTRODUCTIONIntrusion detection technologies began in the early of 1990's.Haystack Labs were the first one to work upon these technologies.They invented tools not only for intrusion detection technologies, also various host based products too.There were various organizations that were developing the IDS system according to their applications.But the end of this era, ASIM became successful in developing solutions related to hardware and software for protection network.With the leap of time intrusion detection technologies become so much commercial that now day's customers have started developing Intrusion Detection technologies for their personal usage.The aim of Intrusion detection System is to defend the security to the Computer system by a layer over the defense system.IDS systems sense the misuse, breach in the security system and also the malicious or unauthorized access to the system.Although Firewalls works for the same reason but the major difference between firewalls and the IDS is IDS suspect the source of the attack and signals the alarm to the system but a firewall directly stops the communication without informing the system.These attacks requires true concerns as they harm the data stored in system and also effect the network traffic, data packet etc. G.V. Nadiammai showed the setup phase by following diagram. II. DATA MINING TECHNIQUES, KDD A. knowledge discoveryVolume data used .The Knowledge discovery in databases (KDD) process is used .step in this process.analyzing data from the data mining.Summarizing it into useful information of data miming.It is the process of finding correlations or patterns amongst dozens of fields in large relational databases.The figure bellows show the different steps for extracting useful data from volume data [8].