Intrusion detection system using an optimized framework based on datamining techniques

Elham Ariafar, Rasoul Kiani · 2017

Nowadays, detection of various attacks constitutes a significant aspect of network security. The task of an intrusion detection system (IDS) is to identify and detect any unauthorized use, exploitation or damage to network resources and systems. In this paper, an optimized framework for network attack detection is presented using data mining techniques. The framework is based on the K-means clustering and decision tree (DT) classification techniques in which a genetic algorithm (GA) is used to optimize such parameters as number of clusters (K), max_runs, and confidence. Simulation results on the NSL-KDD 2009 dataset have revealed that the suggested method achieved a 99.1% of detection rate (DR) and 1.8% of false alarm rate (FAR), demonstrating an improvement compared with the new ensemble clustering (NEC) method.

Read the paper · More papers on PaperTik