Research on IDS Data Fusion Model Based on D-S Evidence Theory

Hongyu Yang, Yanbing Chen · IC3T '12 Proceedings of the 2012 International Conference on Convergence Computer Technology · 2012

To solve the issue of high false positive rate and the false negative rate of traditional intrusion detection systems (IDS), this paper proposes a new IDS model based on support vector machine (SVM) classifiers. According to basic features of TCP, content features and traffic features, network connections are classified by three SVM classifiers, then those classified results are processed as evidence which will be fused together through the combination rule of D-S evidence theory and can be used to detect the network intrusion. The experimental result demonstrates that the model can effectively resolve the issue mentioned above, and improve the comprehensive intrusion detection performance significantly.

Read the paper · More papers on PaperTik