Comparison of Intrusion Detection System Hybrid Approach in Computer Networks with Previous Methods
Mehdi Khodamoradi · International Journal of Engineering and Technology · 2019
Various techniques have been used in designing a misuse detection system among which machine learning algorithm, smart expert systems and statistical methods can be pointed out.This study aims to compare the intrusion detection system hybrid approach in computer networks with previous methods in order to improve attack detection and reduce false alarms.The architecture of the proposed method has three stages.In the first stage, pre-processing data and feature selection using different methods such as information gain and Fisher algorithm, selecting samples was done by using various clustering methods such as self-organizing mapping, K-means clustering and data classification.In the second stage, 4 decision trees classifiers i.e. naïve Bayesian, KNN (K-nearest neighbors) and neural networks were used in order to generate median data.At the third stage, an incremental classification based on decision tree was used.Results show that the proposed hybrid method, relative to both previous individual and combined classifications, are more efficient in detecting denial of service, port scanning, remote to local (R2L) and user to root (U2R) attacks.